In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
{
"cna_assigner": "bcorg",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59650.json",
"cwe_ids": [
"CWE-20"
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59650.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "15458665382500294967819572709069610729",
"length": 1499.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2026-59650-c8dd9437",
"target": {
"file": "core/src/test/java/org/bouncycastle/crypto/test/DHTest.java",
"function": "performTest"
},
"source": "https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148"
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"39837229199252067709863267428376564493",
"89056948157061883310803270858058668336",
"98411027682919515017005145550953223550",
"68609166975825839622195483804635438532",
"97465306179402342352019293947987888651",
"174446942765070382252366940398412439069",
"179180798686791180524949814342786605442",
"132032706204184555523655794045681315998",
"217457557378545958920564931163998102709",
"106139185827831722010841543987112865630",
"324251246715430604868198576214846890368",
"10024155742309374045783853878627013864",
"65464175540726300648816279084747107648",
"106493395332007424881234845227534588094",
"130545261436354824854125595202154121582",
"132993737381193918075780349068224261509",
"119966745500271011262438567101071605900",
"209370374849919101099542497374465528633",
"148009320301020050708507485801545556792",
"166157124020553995644131850085312406270",
"83304957702087655132415981670064896029",
"38169098025588399015197051035299470143",
"86492094171202536628882901750087590791",
"236006963808027379320342124258333742403",
"145421064444035213972389846627766528134",
"209205579286270947472382170165907215349",
"185407259899451598453312194452843096956",
"170088055311645693780096711882901870265",
"105394072204309227281198512899102806394",
"252969760893965287317455560448025290872",
"62414458308160710803745041302001662934",
"148714700210040392342219666206895201268",
"206918780053028883639992426682971096226",
"276110901575714650566962312926294917303",
"224820137487141884433983622436868570036",
"215804546267509209630041151600005197147",
"161374838074741889965706815960646264073",
"89063255969657513393871253650791208268",
"211813012524270769352283450511491380835",
"105414480793944947940510558785717741759"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2026-59650-d061d92e",
"target": {
"file": "core/src/test/java/org/bouncycastle/crypto/test/DHTest.java"
},
"source": "https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148"
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"198002678574329065828187285859489414562",
"219914403672327470544985569536845380476",
"125882156613492703650776123370260850979",
"133724903272672148906466052467860915053",
"257430002790830794627931222844639762238",
"333818514306417897114869158146375367857",
"2474292478684002824468091141837582064",
"26253479406145000584989358973190573257",
"23402125195678913619901665254553391167",
"265753623561889257480922840810398313993",
"36982095808376536006783653477590153189",
"75486295277509996368334464124285110477",
"136132870724656348965355127926120124060",
"86345803385075414509629375505765146304",
"228877134448588105310854659584086457209",
"138796134595921291187794745885110213454",
"151255483941926800790265232073741870661",
"102750529944100940729913550401910346931"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2026-59650-e2b97371",
"target": {
"file": "core/src/main/java/org/bouncycastle/crypto/agreement/DHAgreement.java"
},
"source": "https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148"
},
{
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "289740810013262709615890147309962562743",
"length": 647.0
},
"target": {
"file": "core/src/main/java/org/bouncycastle/crypto/agreement/DHAgreement.java",
"function": "calculateAgreement"
},
"id": "CVE-2026-59650-edb8e1ec"
}
]
"2026-08-12T15:20:50Z"