CVE-2026-59639: CMS verifySignatures returns true for SignedData with zero signers
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59639?
CVE-2026-59639 has a risk rating of 47, indicating a significant security concern.
How do I fix CVE-2026-59639?
To mitigate CVE-2026-59639, upgrade to Bouncy Castle for Java version 1.85 or later, or the appropriate fixed versions of BC-FJA and BC for Java LTS.
What versions are affected by CVE-2026-59639?
CVE-2026-59639 affects Bouncy Castle for Java versions before 1.85, and BC-FJA versions before 1.0.12, 2.0.12, and 2.1.12.
What does CVE-2026-59639 entail?
CVE-2026-59639 allows CMS verifySignatures to incorrectly return true for SignedData with zero signers, potentially leading to security breaches.
Is CVE-2026-59639 a critical vulnerability?
While CVE-2026-59639 is rated significant, its critical impact depends on the context of use and exposure in specific applications.