DH Agreement Vulnerability in Bouncy Castle for Java by Bouncy Castle
CVE-2026-59650

9.3CRITICAL

What is CVE-2026-59650?

An issue has been identified in Bouncy Castle for Java that allows unvalidated peer values during the Diffie-Hellman (DH) agreement process. This flaw can lead to potential security risks, as improper handling of these values could be exploited by malicious actors. Affected versions include Bouncy Castle for Java prior to 1.85 and the LTS version prior to 2.73.12. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability.

Affected Version(s)

BC-JAVA all 0 < 1.85

BC-LTS-JAVA all 2.73.0 < 2.73.12

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor in collaboration with Claude and Anthropic Research
.