CVE-2026-59642: Bouncycastle Bc-Java
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected products
- Bouncycastle Bc-Java: before 1.85 (fixed in 1.85)
- Bouncycastle Bcpkix-Fips: before 1.0.12 (fixed in 1.0.12); from 2.0.7, before 2.0.12 (fixed in 2.0.12); from 2.1.8, before 2.1.12 (fixed in 2.1.12)
- Bouncycastle Bouncy Castle For Java LTS: up to and including 2.73.11
Published 2026-08-03. Last modified 2026-08-28.