Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-59650: Bouncy Castle Java lets attackers manipulate key exchange

CVE-2026-59650 · published 2 months ago
Summary

The Bouncy Castle cryptography library for Java can be tricked into using a malicious value during a key‑exchange process. This could let an attacker weaken or break the encrypted connection. Update to the latest version of the library or apply the vendor’s recommended patches as soon as possible.

What to do
  • Update legion of the bouncy castle inc. bc-java to version 1.85 or later.
  • Update legion of the bouncy castle inc. bc-lts-java to version 2.73.12 or later.
  • Update bouncycastle bc-java to version 1.85 or later.
Affected software
Ecosystem VendorProductAffected versions
– legion of the bouncy castle inc. bc-java < 1.85
– legion of the bouncy castle inc. bc-lts-java < 2.73.12
Debian:11 debian bouncycastle All versions
Debian:12 debian bouncycastle All versions
Debian:13 debian bouncycastle All versions
Debian:14 debian bouncycastle All versions
Ubuntu:Pro:16.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:18.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:20.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:22.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:24.04:LTS canonical bouncycastle All versions
Ubuntu:26.04:LTS canonical bouncycastle All versions
– bouncycastle bc-java < 1.85
cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*
– bouncycastle bouncy_castle_for_java_lts <= 2.73.11
cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*
Original advisory text
MTI/A0 DH agreement exponentiates unvalidated peer value
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
Timeline
Published3 Aug 2026
Updated2 Oct 2026
First seen3 Aug 2026
Track software like this
Free during beta