CVE-2026-59641
Received Received - Intake

S/MIME Path Validation Trust in Bouncy Castle

Vulnerability report for CVE-2026-59641, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
bouncy_castle bouncy_castle_for_java to 1.85 (exc)
bouncy_castle bouncy_castle_for_java_lts to 2.73.12 (exc)
bouncy_castle bouncy_castle_for_java_fips to 1.0.7 (exc)
bouncy_castle bouncy_castle_for_java_fips to 2.0.7 (exc)
bouncy_castle bouncy_castle_for_java_fips to 2.1.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Bouncy Castle for Java before version 1.85 allows S/MIME validator to trust signer-asserted signingTime during path validation. This means the system may accept a certificate as valid based on a timestamp provided by the signer rather than verifying it independently.

Detection Guidance

This vulnerability cannot be directly detected via network or system commands as it involves a flaw in Bouncy Castle's S/MIME validator trusting signer-asserted signingTime for path validation. Detection requires checking the installed version of Bouncy Castle libraries against the affected versions (before 1.85 for Java, before 2.73.12 for LTS, or specific versions for BC-FJA).

Impact Analysis

This vulnerability could allow attackers to bypass certificate validation by providing a fake signingTime. This might lead to man-in-the-middle attacks, unauthorized access, or data interception if exploited.

Compliance Impact

The vulnerability allows S/MIME path validation to trust signer-asserted signingTime, which could lead to improper validation of digital signatures. This may result in non-compliance with data integrity and authenticity requirements in standards like GDPR and HIPAA, where proper validation of signed communications is critical.

Mitigation Strategies

Upgrade Bouncy Castle for Java to version 1.85 or later, Bouncy Castle for Java LTS to 2.73.12 or later, and Bouncy Castle for Java FIPS to bcmail-fips and bcjmail-fips 1.0.7, 2.0.7, or 2.1.7 or later versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59641. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart