7.5
CVE-2026-59646
- EPSS 0.29%
- Veröffentlicht 03.08.2026 00:48:29
- Zuletzt bearbeitet 28.08.2026 19:57:57
- Erkennungen
DTLS handshake reassembler allocates buffer from unchecked 24-bit length
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version < 1.85
Bouncycastle ≫ Bctls-fips Version < 1.0.24
Bouncycastle ≫ Bctls-fips Version >= 2.0.19 < 2.0.24
Bouncycastle ≫ Bctls-fips Version >= 2.1.20 < 2.1.24
Bouncycastle ≫ Bouncy Castle For Java Lts Version <= 2.73.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.214 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| 91579145-5d7b-4cc5-b925-a0262ff19630 | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://github.com/bcgit/bc-java/commit/2ea38942c7917f6d7ab4de93d8a5336d021df0d9
https://github.com/bcgit/bc-java/commit/2d98721e71bbd822ffa0f84e088eea645cf679fa
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059646