LOWVulnerability
CVE-2026-59639
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Properties
- cve_id
- CVE-2026-59639
- published_at
- 2026-08-03T01:16:43.700
- last_modified
- 2026-08-04T14:50:12.360
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Verification of Cryptographic Signature
Explore deeper with Ninja Signal's threat intelligence graph