CVE-2026-59649
Received Received - Intake

Memory Bounded OpenPGP User-Attribute Subpacket in Bouncy Castle

Vulnerability report for CVE-2026-59649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
bouncy_castle bouncy_castle to 1.85 (exc)
bouncy_castle bouncy_castle_lts to 2.73.12 (exc)
bouncy_castle bcpg_fips to 1.0.13 (exc)
bouncy_castle bcpg_fips to 2.0.13 (exc)
bouncy_castle bcpg_fips to 2.1.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Bouncy Castle for Java allows an attacker to craft a malicious OpenPGP user-attribute subpacket with a length that can exceed normal bounds, potentially consuming excessive JVM memory. This could lead to denial-of-service conditions by exhausting system resources.

Detection Guidance

This vulnerability involves improper handling of OpenPGP user-attribute subpacket lengths in Bouncy Castle libraries. Detection requires checking library versions and analyzing memory usage patterns during PGP operations. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

If exploited, this vulnerability could cause applications using affected Bouncy Castle versions to crash or become unresponsive due to high memory consumption. It may also lead to degraded performance or system instability in environments processing OpenPGP data.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing excessive memory consumption through maliciously crafted OpenPGP user-attribute subpackets. This may lead to denial-of-service conditions or unauthorized resource exhaustion, which could interfere with data integrity and availability requirements.

Mitigation Strategies

Update Bouncy Castle for Java to version 1.85 or later, Bouncy Castle LTS to 2.73.12 or later, or BC-FJA to the latest series (1.0.13, 2.0.13, 2.1.13).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart