7.5
CVE-2026-59642
- EPSS 0.16%
- Veröffentlicht 03.08.2026 00:53:28
- Zuletzt bearbeitet 28.08.2026 18:12:17
- Erkennungen
CMS AuthenticatedData content not bound to MAC when authAttrs present
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version < 1.85
Bouncycastle ≫ Bcpkix-fips Version < 1.0.12
Bouncycastle ≫ Bcpkix-fips Version >= 2.0.7 < 2.0.12
Bouncycastle ≫ Bcpkix-fips Version >= 2.1.8 < 2.1.12
Bouncycastle ≫ Bouncy Castle For Java Lts Version <= 2.73.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.053 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| 91579145-5d7b-4cc5-b925-a0262ff19630 | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
|
CWE-354 Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059642