What is CVE-2026-59645?
A vulnerability in Bouncy Castle for Java's OER parser allows unbounded recursion on self-referential IEEE 1609.2 schemas due to a missing depth limit. This can lead to denial-of-service (DoS) attacks. Users should upgrade to version 1.85, LTS 2.73.12, or the specified FIPS module versions.
Azərbaycanca: Bouncy Castle Java kitabxanasında OER parser-in özünə istinad edən IEEE 1609.2 sxemini emal edərkən rekursiya dərinliyi limitinin olmaması zəifliyi aşkarlanıb. Bu, xüsusi hazırlanmış verilənlərlə xidmət əleyhinə (DoS) hücumlara səbəb ola bilər. Təsirə məruz qalan versiyalardan 1.85, LTS 2.73.12 və FIPS modullarının göstərilən versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
How can I protect against CVE-2026-59645 in Bouncy Castle for Java?
You should upgrade to version 1.85, LTS 2.73.12, or the corresponding FIPS module versions.
Which component is affected by CVE-2026-59645?
The vulnerability is in the OER parser when processing self-referential IEEE 1609.2 schemas due to a missing recursion depth limit.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.