What is CVE-2026-59649?
This vulnerability exists in Bouncy Castle's OpenPGP implementation where the user-attribute subpacket length is bounded only by JVM max memory, leading to potential resource exhaustion. It affects Bouncy Castle for Java before 1.85, LTS before 2.73.12, and FIPS (BC-FJA) versions before specific bcpg-fips releases. Users should upgrade to the patched versions.
Azərbaycanca: Bu zəiflik Bouncy Castle kitabxanasının OpenPGP tətbiqində aşkarlanıb və user-attribute subpacket uzunluğunun yalnız JVM maksimum yaddaşı ilə məhdudlaşmasından qaynaqlanır. Təsirə məruz qalan versiyalar Java üçün Bouncy Castle 1.85-dən əvvəlki, LTS 2.73.12-dən əvvəlki və FIPS versiyalarıdır. İstifadəçilər qeyd olunan versiyalara yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
What is the cause of the CVE-2026-59649 vulnerability found in Bouncy Castle?
The vulnerability exists because the user-attribute subpacket length in Bouncy Castle's OpenPGP implementation is bounded only by JVM max memory.
Which Bouncy Castle versions should be upgraded to mitigate CVE-2026-59649?
Users should upgrade to Bouncy Castle for Java 1.85, LTS 2.73.12, and the relevant patched FIPS versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.