In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
{
"cwe_ids": [
"CWE-326"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59651.json",
"cna_assigner": "bcorg"
}[
{
"digest": {
"line_hashes": [
"15148027283377381719596940514532161111",
"172975123313478698404074341700957063612",
"109023459789284408156035779380756745775",
"151272244620854793997818626639231338731",
"222668592509052525732416211609475159460",
"182908047630165293122201298941211064790",
"108166492819978185386172275580323855728",
"77104941461503250714631581004896477385"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java"
},
"deprecated": false,
"id": "CVE-2026-59651-40b6539c",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Line"
},
{
"target": {
"file": "core/src/main/java/org/bouncycastle/util/Properties.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"96684826020611684918059161827084495306",
"57992135761685036526460799104499525190",
"9171158972804423024463371601289381102"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-59651-530cd286",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "Version1"
},
"deprecated": false,
"digest": {
"function_hash": "204634527083799087084619359693818727199",
"length": 148.0
},
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"id": "CVE-2026-59651-5cc7f000",
"signature_type": "Function"
},
{
"digest": {
"function_hash": "61707722736170827498596593609030394387",
"length": 1379.0
},
"signature_version": "v1",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
"function": "engineLoad"
},
"deprecated": false,
"id": "CVE-2026-59651-8561de62",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Function"
},
{
"target": {
"file": "prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java",
"function": "performTest"
},
"deprecated": false,
"digest": {
"function_hash": "213771027295792638980630556704308590835",
"length": 187.0
},
"signature_version": "v1",
"id": "CVE-2026-59651-d9c2ebab",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Function"
},
{
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/BC.java",
"function": "configure"
},
"deprecated": false,
"digest": {
"function_hash": "177240300101857186818577509190558340152",
"length": 556.0
},
"signature_version": "v1",
"id": "CVE-2026-59651-ea836f2b",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"225045895620779628659577344791053302128",
"237492543990238882119151666139201558605",
"142154336802530442028021593140917019486",
"269825138758587411159333109661907010681",
"95468557848830955397198037702185932109",
"69304884728371620684480431497444532775",
"170679917142571855638708020955833093402",
"42926264764225358295138698427494267140",
"75766635981602846335404847046623381326",
"5408560579965433786011845734491725340",
"135601120802384019292767943224476591628"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java"
},
"deprecated": false,
"id": "CVE-2026-59651-fe3fbe31",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Line"
},
{
"target": {
"file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/BC.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"76867312987272014725145402352593474555",
"61061512128438956846901448712588188473",
"184967030617686960743669963089157358559",
"282426976527023415072742618538076290076"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-59651-fee2ac32",
"source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59651.json"
"2026-08-12T15:20:50Z"