In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
{
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59647.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.12"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.12"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.12"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "bcorg"
}[
{
"digest": {
"line_hashes": [
"311364422625888269058408095146596687366",
"309579080998695119046925374867626751876",
"129798592693657596835692987390861036897"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "core/src/main/java/org/bouncycastle/util/Properties.java"
},
"deprecated": false,
"id": "CVE-2026-59647-112e1637",
"source": "https://github.com/bcgit/bc-java/commit/c99d6427d6818d04165b07b45dfda96f2b384c53",
"signature_type": "Line"
},
{
"id": "CVE-2026-59647-466b4290",
"signature_version": "v1",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cert/crmf/PKMACBuilder.java"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/c99d6427d6818d04165b07b45dfda96f2b384c53",
"digest": {
"line_hashes": [
"282034187603892256663863769691837681373",
"263521362359616960025411099985319982991",
"115497456215366362001201246592857730270",
"46416603333340295309544677322578512512",
"53889960897588887475492976421895266829",
"37737357403438712424962845174505027396",
"47489986048131552733075460851433114733",
"28419601338975652127744579826109286569",
"102878209774513247431403751761087297209",
"77256309732579255215269448706414049418"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cert/crmf/test/AllTests.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"332962983452388081120875387603598265973",
"24547425068298275282899283791829706213",
"187523879037815365199504240322801473252",
"289167470408123512763983680959001897817",
"201658720830234008980522847271740867412",
"21817322581335455952578260982030694434",
"308207455669245876460953481043343850053",
"103596030790652456631271192219372070868"
],
"threshold": 0.9
},
"source": "https://github.com/bcgit/bc-java/commit/c99d6427d6818d04165b07b45dfda96f2b384c53",
"id": "CVE-2026-59647-5dec0a9e",
"signature_type": "Line"
},
{
"id": "CVE-2026-59647-c33bb89f",
"signature_version": "v1",
"target": {
"file": "pkix/src/main/java/org/bouncycastle/cert/crmf/PKMACBuilder.java",
"function": "checkIterationCountCeiling"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/c99d6427d6818d04165b07b45dfda96f2b384c53",
"digest": {
"function_hash": "57690285400429947527907924685401660647",
"length": 185.0
},
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59647.json"
"2026-08-12T15:20:50Z"