CVE-2026-59651

Source
https://cve.org/CVERecord?id=CVE-2026-59651
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59651.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-59651
Downstream
Related
Published
2026-08-03T00:41:23.578Z
Modified
2026-08-14T18:56:27.614906158Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
BKS keystore accepts legacy version with 16-bit integrity MAC key
Details

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Database specific
{
    "cwe_ids": [
        "CWE-326"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59651.json",
    "cna_assigner": "bcorg"
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.85"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
r1rv73
r1rv74
r1rv75
r1rv76
r1rv77
r1rv78
r1rv80
r1rv81
r1rv82
r1rv83
r1rv84
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

vanir_signatures
[
    {
        "digest": {
            "line_hashes": [
                "15148027283377381719596940514532161111",
                "172975123313478698404074341700957063612",
                "109023459789284408156035779380756745775",
                "151272244620854793997818626639231338731",
                "222668592509052525732416211609475159460",
                "182908047630165293122201298941211064790",
                "108166492819978185386172275580323855728",
                "77104941461503250714631581004896477385"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java"
        },
        "deprecated": false,
        "id": "CVE-2026-59651-40b6539c",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "core/src/main/java/org/bouncycastle/util/Properties.java"
        },
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "96684826020611684918059161827084495306",
                "57992135761685036526460799104499525190",
                "9171158972804423024463371601289381102"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "id": "CVE-2026-59651-530cd286",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
            "function": "Version1"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "204634527083799087084619359693818727199",
            "length": 148.0
        },
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "id": "CVE-2026-59651-5cc7f000",
        "signature_type": "Function"
    },
    {
        "digest": {
            "function_hash": "61707722736170827498596593609030394387",
            "length": 1379.0
        },
        "signature_version": "v1",
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/bc/BcKeyStoreSpi.java",
            "function": "engineLoad"
        },
        "deprecated": false,
        "id": "CVE-2026-59651-8561de62",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java",
            "function": "performTest"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "213771027295792638980630556704308590835",
            "length": 187.0
        },
        "signature_version": "v1",
        "id": "CVE-2026-59651-d9c2ebab",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/BC.java",
            "function": "configure"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "177240300101857186818577509190558340152",
            "length": 556.0
        },
        "signature_version": "v1",
        "id": "CVE-2026-59651-ea836f2b",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Function"
    },
    {
        "digest": {
            "line_hashes": [
                "225045895620779628659577344791053302128",
                "237492543990238882119151666139201558605",
                "142154336802530442028021593140917019486",
                "269825138758587411159333109661907010681",
                "95468557848830955397198037702185932109",
                "69304884728371620684480431497444532775",
                "170679917142571855638708020955833093402",
                "42926264764225358295138698427494267140",
                "75766635981602846335404847046623381326",
                "5408560579965433786011845734491725340",
                "135601120802384019292767943224476591628"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "target": {
            "file": "prov/src/test/java/org/bouncycastle/jce/provider/test/KeyStoreTest.java"
        },
        "deprecated": false,
        "id": "CVE-2026-59651-fe3fbe31",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jcajce/provider/keystore/BC.java"
        },
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "76867312987272014725145402352593474555",
                "61061512128438956846901448712588188473",
                "184967030617686960743669963089157358559",
                "282426976527023415072742618538076290076"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "id": "CVE-2026-59651-fee2ac32",
        "source": "https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2",
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59651.json"
vanir_signatures_modified
"2026-08-12T15:20:50Z"