What is CVE-2026-59646?
In Bouncy Castle for Java, the DTLS handshake reassembler allocates a buffer from an unchecked 24-bit length, potentially leading to memory exhaustion or denial-of-service. This affects versions before 1.85, LTS before 2.73.12, and FIPS modules prior to their respective patched releases. Update to the fixed versions.
Azərbaycanca: Bouncy Castle Java kitabxanasında DTLS handshake reassembler komponenti 24-bit uzunluğu yoxlamadan buffer üçün yaddaş ayırır. Bu, yaddaş tükənməsi və ya xidmət dayanmasına səbəb ola bilər. Versiyanızı 1.85, LTS 2.73.12 və ya müvafiq FIPS yeniləmələrinə yüksəldin.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
In which component of the Bouncy Castle for Java library was CVE-2026-59646 discovered?
This vulnerability was discovered in the DTLS handshake reassembler component, as it allocates a buffer from an unchecked 24-bit length.
To which versions should I upgrade to protect against CVE-2026-59646?
You should upgrade to version 1.85, LTS 2.73.12, or the respective patched releases of the FIPS modules.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.