What is CVE-2026-59650?
CVE-2026-59650 is a vulnerability in Bouncy Castle for Java where the MTI/A0 DH agreement exponentiates an unvalidated peer value. It affects versions before 1.85 and LTS versions before 2.73.12. Affected systems should be upgraded to the latest patched release.
Azərbaycanca: CVE-2026-59650, Bouncy Castle for Java kitabxanasında MTI/A0 DH razılaşması zamanı etibarsız peer dəyərinin eksponentasiyasına yol açan boşluqdur. Bu zəiflik 1.85-dən əvvəlki versiyalara və LTS 2.73.12-dən əvvəlki versiyalara təsir göstərir. Təsirlənən sistemlərin ən son versiyaya yenilənməsi tövsiyə olunur.
FAQ2
Through which mechanism is CVE-2026-59650 exploited in Bouncy Castle for Java?
The vulnerability is exploited through the exponentiation of an unvalidated peer value during the MTI/A0 DH agreement.
Which Bouncy Castle for Java versions are affected by CVE-2026-59650?
Versions before 1.85 and LTS versions before 2.73.12 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.