What is CVE-2026-59647?
This vulnerability in Bouncy Castle for Java allows an unbounded iteration count in the CRMF/CMP password-MAC mechanism. This could enable an attacker to cause excessive CPU consumption, leading to a potential Denial of Service (DoS). It is recommended to update to the specified patched versions to mitigate the issue.
Azərbaycanca: Bu zəiflik Bouncy Castle for Java kitabxanasının CRMF/CMP password-MAC mexanizmində limitsiz iterasiya sayına icazə verir. Bu, hücumçuya həddindən artıq CPU resursu istehlak edərək Denial of Service (DoS) hücumu təşkil etməyə imkan yarada bilər. Zəiflikdən qorunmaq üçün kitabxananı göstərilən versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which mechanism in the Bouncy Castle for Java library allows an unbounded iteration count?
This vulnerability allows an unbounded iteration count in the CRMF/CMP password-MAC mechanism.
What type of attack could CVE-2026-59647 lead to?
This vulnerability could cause excessive CPU consumption, leading to a potential Denial of Service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.