CVE-2026-59645
Received Received - Intake

Stack Overflow in Bouncy Castle for Java

Vulnerability report for CVE-2026-59645, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
bouncy_castle bouncy_castle to 1.85 (exc)
bouncy_castle bouncy_castle_lts to 2.73.12 (exc)
bouncy_castle bcutil_fips to 2.0.7 (exc)
bouncy_castle bcutil_fips to 2.1.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an OER parser in Bouncy Castle for Java that recurses without a depth limit when processing self-referential IEEE 1609.2 schema. This can lead to a stack overflow or denial of service due to infinite recursion.

Impact Analysis

The vulnerability can cause application crashes or system instability by triggering excessive recursion, potentially leading to denial of service. It affects systems using vulnerable versions of Bouncy Castle for Java, LTS, or FIPS libraries.

Compliance Impact

This vulnerability involves a recursion issue in the OER parser of Bouncy Castle for Java, which could lead to denial-of-service conditions due to unbounded recursion on self-referential schemas. While this may impact system availability, there is no direct evidence in the provided context that this vulnerability specifically affects compliance with GDPR, HIPAA, or other standards.

Mitigation Strategies

Upgrade Bouncy Castle for Java to version 1.85 or later. For LTS versions, upgrade to 2.73.12 or later. For BC-FJA, upgrade to bcutil-fips 2.0.7 (2.0.X series) or 2.1.7 (2.1.X series).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59645. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart