OpenPGP Inline-Signature Policy Issues in Bouncy Castle Java Library
CVE-2026-59643

8.7HIGH

What is CVE-2026-59643?

The Bouncy Castle library for Java prior to version 1.85 has a vulnerability related to OpenPGP inline-signature policy failures that are silently ignored. This oversight can pose significant risks to the integrity of signed messages, as users may unknowingly accept signatures that do not adhere to expected policies. Additionally, the Bouncy Castle FIPS variant (bcpg-fips) is also affected if it is running versions earlier than 2.0.13, potentially compromising cryptographic operations. It is crucial for users of this library to update to the latest versions to mitigate risks associated with this vulnerability.

Affected Version(s)

BC-FJA all 2.0.12 < 2.0.13

BC-JAVA all 1.81 < 1.85

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor in collaboration with Claude and Anthropic Research
.