CVE-2026-59651(bouncycastle / bc-java)

LOWCVSS 7.5 · HIGH

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-326

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bc-java
  • bouncy_castle_for_java_lts

Affected systems

Products
bc-javabouncy_castle_for_java_lts

Deep dive

Full discourse1 post
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-59651 BKS Keystore Legacy Version Integrity MAC Key Vulnerability in Bouncy Castle for Java https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-59651

    Post summary

    The text simply notes CVE-2026-59651 as a BKS Keystore Integrity MAC Key vulnerability in Bouncy Castle for Java and links to a vulnerability details page, with no PoC, exploit, or mitigation information provided.

    00000100
    4.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbouncycastlebc-java---
Appbouncycastlebouncy_castle_for_java_lts---

Explore more