What is CVE-2026-59651?
In Bouncy Castle for Java, the BKS keystore accepts legacy versions with a 16-bit integer and a 16-bit integrity MAC key, which is a security weakness. This affects versions before 1.85 and LTS before 2.73.12; users should update to the fixed versions.
Azərbaycanca: Bouncy Castle Java kitabxanasında BKS keystore-un 16-bit int və zəif MAC açarı olan köhnə versiyaları qəbul etməsi zəifliyidir. Bu, 1.85 və LTS 2.73.12-dən əvvəlki versiyalara təsir edir; yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ1
Which component in the Bouncy Castle for Java library is affected by CVE-2026-59651?
This vulnerability affects the BKS keystore component of Bouncy Castle. The acceptance of legacy BKS keystores using a 16-bit integer and a 16-bit integrity MAC key creates a security weakness.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.