CVE-2026-59640: OpenPGP CFB quick-check oracle active on symmetric/session-key paths
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59640?
CVE-2026-59640 has a risk rating of 47, indicating a moderate level of severity.
How do I fix CVE-2026-59640?
To fix CVE-2026-59640, upgrade to Bouncy Castle for Java version 1.85 or later, or the appropriate versions for LTS and FIPS.
What systems are affected by CVE-2026-59640?
CVE-2026-59640 affects Bouncy Castle for Java versions before 1.85, Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS versions before 1.0.13, 2.0.13, and 2.1.13.
What is the impact of CVE-2026-59640?
The impact of CVE-2026-59640 allows an attacker to exploit the OpenPGP CFB quick-check oracle which could lead to security breaches.
Is there a workaround for CVE-2026-59640?
There is no specific workaround for CVE-2026-59640; upgrading to the fixed version is recommended.