CVE-2026-59641: S/MIME validator trusts signer-asserted signingTime for path validation
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59641?
The severity of CVE-2026-59641 is rated at 47.
How do I fix CVE-2026-59641?
To fix CVE-2026-59641, upgrade to Bouncy Castle for Java version 1.85 or later, or the respective LTS and FIPS versions.
What systems are affected by CVE-2026-59641?
CVE-2026-59641 affects Bouncy Castle for Java prior to version 1.85, Bouncy Castle for Java LTS prior to 2.73.12, and Bouncy Castle for Java FIPS prior to bcmail-fips and bcjmail-fips 1.0.7 and 2.0.7.
What is the impact of CVE-2026-59641 on applications?
CVE-2026-59641 allows the S/MIME validator to trust potentially unreliable signer-asserted signingTime, which can lead to security risks in path validation.
When was CVE-2026-59641 published?
CVE-2026-59641 was published on August 3, 2026.