What is CVE-2026-59644?
CVE-2026-59644 is a vulnerability in Bouncy Castle for Java versions before 1.85 where the MLS hash-ratchet honors an arbitrary 32-bit generation counter from the sender. Affected systems should upgrade to version 1.85 to mitigate the risk.
Azərbaycanca: CVE-2026-59644 Bouncy Castle for Java 1.85 əvvəlki versiyalarında MLS hash-ratchet mexanizmində göndərəndən gələn 32-bitlik generasiya sayğacını ixtiyari qəbul etməsi ilə bağlı zəiflikdir. Təsirə məruz qalan sistemlərdə bu boşluq təhlükəsizlik riski yaradır, istifadəçilərə versiyanı 1.85-ə yüksəltmək tövsiyə olunur.
FAQ2
In which component was CVE-2026-59644 discovered?
This vulnerability was discovered in the MLS hash-ratchet mechanism of the Bouncy Castle for Java library.
To which version should users upgrade to mitigate CVE-2026-59644?
Users are advised to upgrade the Bouncy Castle library to version 1.85.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.