CVE-2026-13506: Lazy ASN.1 sequence forcing resets nesting-depth guard
Published Aug 3, 2026
·Updated
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected Software
3 affected components
Bouncy Castle Bouncy Castle for Java<1.85
Bouncy Castle Bouncy Castle for Java LTS<2.73.12
Bouncy Castle Bouncy Castle for Java FIPS (BC-FJA)>1.0.2.6<=1.0.2.6, <1.0.2.7, <2.0.2, <2.1.3
Event History
Aug 3, 2026
CVE Published
via MITRE·02:56 AM
Data Sourced
via MITRE·02:56 AM
DescriptionWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13506?
CVE-2026-13506 has a high severity rating of 8.7.
2
How do I fix CVE-2026-13506?
To fix CVE-2026-13506, update to Bouncy Castle for Java version 1.85 or later.
3
What software is affected by CVE-2026-13506?
CVE-2026-13506 affects Bouncy Castle for Java, Bouncy Castle for Java LTS, and Bouncy Castle for Java FIPS prior to specific versions.
4
What is the risk associated with CVE-2026-13506?
CVE-2026-13506 has a risk rating of 47, indicating significant exposure to potential attacks.
5
When was CVE-2026-13506 published?
CVE-2026-13506 was published on August 3, 2026.