What is CVE-2026-59648?
A vulnerability in Bouncy Castle for Java allows the OpenPGP Argon2 S2K function to accept attacker-chosen memory and passes parameters. This can lead to a Denial of Service (resource exhaustion) attack. It is recommended to update to the patched versions across the main, LTS, and FIPS distributions.
Azərbaycanca: Bouncy Castle Java kitabxanasında OpenPGP Argon2 S2K funksiyası, hücumçunun seçdiyi arqumentləri (memory and passes) qəbul edir. Bu, resurs istehlakına əsaslanan DoS hücumlarına səbəb ola bilər. Versiyanızı müvafiq LTS, FIPS seriyalarına aid patched versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
Which function in Bouncy Castle for Java is affected by CVE-2026-59648?
This vulnerability affects the OpenPGP Argon2 S2K function.
What is the impact of CVE-2026-59648?
This vulnerability can lead to a Denial of Service (resource exhaustion) attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.