CVE-2026-59648: OpenPGP Argon2 S2K honours attacker-chosen memory and passes
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59648?
The severity of CVE-2026-59648 is rated at risk level 33.
How do I fix CVE-2026-59648?
To fix CVE-2026-59648, upgrade to Bouncy Castle for Java version 1.85 or later, or to Bouncy Castle for Java LTS version 2.73.12 or later.
Which versions of Bouncy Castle are affected by CVE-2026-59648?
CVE-2026-59648 affects Bouncy Castle for Java versions before 1.85, Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS before specified patch versions.
Does CVE-2026-59648 allow an attacker any capabilities?
Yes, CVE-2026-59648 allows an attacker to influence the memory and passes chosen in OpenPGP Argon2 S2K.
What are the implications of exploiting CVE-2026-59648?
Exploiting CVE-2026-59648 may lead to weakened cryptographic protections in applications using the affected Bouncy Castle libraries.