OpenPGP Inline-Signature Policy Issues in Bouncy Castle Java Library
CVE-2026-59643
8.7HIGH
Key Information:
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-59643?
The Bouncy Castle library for Java prior to version 1.85 has a vulnerability related to OpenPGP inline-signature policy failures that are silently ignored. This oversight can pose significant risks to the integrity of signed messages, as users may unknowingly accept signatures that do not adhere to expected policies. Additionally, the Bouncy Castle FIPS variant (bcpg-fips) is also affected if it is running versions earlier than 2.0.13, potentially compromising cryptographic operations. It is crucial for users of this library to update to the latest versions to mitigate risks associated with this vulnerability.
Affected Version(s)
BC-FJA all 2.0.12 < 2.0.13
BC-JAVA all 1.81 < 1.85
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Gaynor in collaboration with Claude and Anthropic Research
