CVE-2026-59642

Source
https://cve.org/CVERecord?id=CVE-2026-59642
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59642.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-59642
Downstream
Related
Published
2026-08-03T00:53:28.335Z
Modified
2026-08-14T18:56:22.200295521Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
CMS AuthenticatedData content not bound to MAC when authAttrs present
Details

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "fixed": "1.0.12"
                },
                {
                    "introduced": "2.0.0"
                },
                {
                    "fixed": "2.0.12"
                },
                {
                    "introduced": "2.1.0"
                },
                {
                    "fixed": "2.1.12"
                }
            ]
        }
    ],
    "cna_assigner": "bcorg",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59642.json",
    "cwe_ids": [
        "CWE-354"
    ]
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.85"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
r1rv73
r1rv74
r1rv75
r1rv76
r1rv77
r1rv78
r1rv80
r1rv81
r1rv82
r1rv83
r1rv84
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59642.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "158098705894453175611627068209439252856",
            "length": 132.0
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "id": "CVE-2026-59642-4af0222a",
        "target": {
            "file": "pkix/src/main/java/org/bouncycastle/cms/RecipientInformation.java",
            "function": "getContentDigest"
        },
        "source": "https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7"
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "150217748446945654414047803362711950934",
                "1998123424796623913195565977078044746",
                "207441397873051006056980075182668530100",
                "203396658360276607175417645139980351604",
                "113712877113581979010122924401452900987",
                "13711302224811139093065775823879479406",
                "56554506495746184650441532241253947666"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "id": "CVE-2026-59642-6b09abcb",
        "target": {
            "file": "pkix/src/test/java/org/bouncycastle/cms/test/NewAuthenticatedDataTest.java"
        },
        "source": "https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7"
    },
    {
        "deprecated": false,
        "source": "https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "61699490159765602539153070249759677197",
                "56560191882192937615218115731037239263",
                "24036779943014696142836835206958396516",
                "33232504576858798088661092056725251803",
                "327868872123641563172476653506726869357",
                "200306090724297130737187927307177303609",
                "249104143113737347786098795121604856891",
                "55391454397317711969786491273130876631",
                "170557251947484495234519101514996299858",
                "112480898048311352422068928879973531591",
                "289738783927282737255034759486543674197",
                "337373655030248289854707050470073004410",
                "268291835428421863060575012389967153192",
                "43519609951270477486745825511230203846",
                "212672181796388980001766427326571141286",
                "49742308220545660429250441296731924397",
                "339057762577795336572375973345520552834",
                "63906742431382576774228129428346309006",
                "303969752525948689698502435476128370615",
                "37558898415141351238041908027039281359",
                "79072122845672055724788783194961531788",
                "48481253750998680472344962314752678478",
                "127622876659552018766340612939383498150",
                "227406516074827410903372648830531917029"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "pkix/src/main/java/org/bouncycastle/cms/RecipientInformation.java"
        },
        "id": "CVE-2026-59642-c3221fa8"
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "40463559588436642954628715187378232437",
            "length": 404.0
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "id": "CVE-2026-59642-f992e9be",
        "target": {
            "file": "pkix/src/main/java/org/bouncycastle/cms/RecipientInformation.java",
            "function": "getMac"
        },
        "source": "https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7"
    }
]
vanir_signatures_modified
"2026-08-12T15:20:49Z"