CVE-2026-59639

EUVD-2026-52035
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.97%
Affected Products (NVD)
VendorProductVersion
bouncycastlebc-java
𝑥
< 1.85
bouncycastlebcpkix-fips
𝑥
< 1.0.12
bouncycastlebcpkix-fips
2.0.7 ≤
𝑥
< 2.0.12
bouncycastlebcpkix-fips
2.1.8 ≤
𝑥
< 2.1.12
bouncycastlebouncy_castle_for_java_lts
𝑥
≤ 2.73.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bouncycastle
bookworm
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bouncycastle
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
bouncycastle
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed
bouncycastle-javadoc
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed
bouncycastle-mail
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed
bouncycastle-pg
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed
bouncycastle-pkix
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed
bouncycastle-tls
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed
bouncycastle-util
Amazon Linux 2023
0:1.70-4.amzn2023.0.8
fixed