Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-59650: Bouncy Castle Java lets attackers manipulate key exchange
CVE-2026-59650 · published 2 months ago
Summary
The Bouncy Castle cryptography library for Java can be tricked into using a malicious value during a key‑exchange process. This could let an attacker weaken or break the encrypted connection. Update to the latest version of the library or apply the vendor’s recommended patches as soon as possible.
What to do
- Update legion of the bouncy castle inc. bc-java to version 1.85 or later.
- Update legion of the bouncy castle inc. bc-lts-java to version 2.73.12 or later.
- Update bouncycastle bc-java to version 1.85 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | legion of the bouncy castle inc. | bc-java | < 1.85 |
| – | legion of the bouncy castle inc. | bc-lts-java | < 2.73.12 |
| Debian:11 | debian | bouncycastle | All versions |
| Debian:12 | debian | bouncycastle | All versions |
| Debian:13 | debian | bouncycastle | All versions |
| Debian:14 | debian | bouncycastle | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:26.04:LTS | canonical | bouncycastle | All versions |
| – | bouncycastle | bc-java |
< 1.85 cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* |
| – | bouncycastle | bouncy_castle_for_java_lts |
<= 2.73.11 cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:* |
Original advisory text
MTI/A0 DH agreement exponentiates unvalidated peer value
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
References
- https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148 Patch
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59650
- https://github.com/bcgit/bc-java Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-59650 Vendor Advisory
- https://www.bouncycastle.org/download/bouncy-castle-java/ URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59650... Vendor Advisory
- https://www.bouncycastle.org/download/bouncy-castle-java-lts/ URL
- https://github.com/bcgit/bc-lts-java Product
- https://security-tracker.debian.org/tracker/CVE-2026-59650 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-59650 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-59650 Third Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059650 Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-20Improper Input Validation
Timeline
Published3 Aug 2026
Updated2 Oct 2026
First seen3 Aug 2026
Sources
CVE-2026-59650 · NVD
CVE-2026-59650 · MITRE
CVE-2026-59650 · OSV
DEBIAN-CVE-2026-59650 · OSV
UBUNTU-CVE-2026-59650 · OSV
Track software like this
Free during beta