CVE-2026-59647: CRMF/CMP password-MAC honours unbounded iteration count
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59647?
CVE-2026-59647 has a risk rating of 33.
How do I fix CVE-2026-59647?
To remediate CVE-2026-59647, update Bouncy Castle for Java to version 1.85 or later, or ensure you are using Bouncy Castle for Java LTS version 2.73.12 or later.
Which versions are affected by CVE-2026-59647?
CVE-2026-59647 affects Bouncy Castle for Java versions before 1.85, Bouncy Castle for Java LTS before 2.73.12, and specific versions of Bouncy Castle for Java FIPS before 1.0.12, 2.0.12, and 2.1.12.
What type of vulnerability is CVE-2026-59647?
CVE-2026-59647 is a vulnerability related to the handling of unbounded iteration counts in CRMF/CMP password-MAC.
Is CVE-2026-59647 an issue for both Java and FIPS implementations?
Yes, CVE-2026-59647 affects both Bouncy Castle for Java and its FIPS-compliant versions.