DH Agreement Vulnerability in Bouncy Castle for Java by Bouncy Castle
CVE-2026-59650
9.3CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-59650?
An issue has been identified in Bouncy Castle for Java that allows unvalidated peer values during the Diffie-Hellman (DH) agreement process. This flaw can lead to potential security risks, as improper handling of these values could be exploited by malicious actors. Affected versions include Bouncy Castle for Java prior to 1.85 and the LTS version prior to 2.73.12. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability.
Affected Version(s)
BC-JAVA all 0 < 1.85
BC-LTS-JAVA all 2.73.0 < 2.73.12
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Gaynor in collaboration with Claude and Anthropic Research
