Password-MAC Vulnerability in Bouncy Castle Java Library
CVE-2026-59647

6.9MEDIUM

What is CVE-2026-59647?

A vulnerability in earlier versions of the Bouncy Castle for Java cryptography library allows the password-MAC feature to honor unbounded iteration counts in CRMF/CMP operations. This issue may lead to potential security risks and could compromise secure password handling, impacting applications relying on the library for cryptographic operations. Users are advised to update to the latest versions to mitigate potential threats.

Affected Version(s)

BC-FJA all 1.0.0 < 1.0.12

BC-FJA all 2.0.0 < 2.0.12

BC-FJA all 2.1.0 < 2.1.12

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor in collaboration with Claude and Anthropic Research
.