CVE-2026-13586: PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13586?
The severity of CVE-2026-13586 is rated as medium with a CVSS score of 5.3.
How does CVE-2026-13586 affect Bouncy Castle libraries?
CVE-2026-13586 affects Bouncy Castle for Java versions prior to 1.85, as well as certain LTS and FIPS versions.
What type of vulnerability is CVE-2026-13586?
CVE-2026-13586 is a denial-of-service (DoS) vulnerability related to PKCS#12 MAC and bag-decryption KDF iteration-count bounds.
How can I mitigate CVE-2026-13586?
To mitigate CVE-2026-13586, you should upgrade to Bouncy Castle for Java version 1.85 or later.
Are there any specific versions of Bouncy Castle to update for CVE-2026-13586?
Yes, you should update Bouncy Castle for Java LTS to at least version 2.73.12 and BC-FJA to at least its respective versions specified.