CVE-2026-59649: OpenPGP user-attribute subpacket length bounded only by JVM max memory
In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59649?
CVE-2026-59649 has a risk rating of 33, indicating a moderate severity level.
What systems are affected by CVE-2026-59649?
CVE-2026-59649 affects Bouncy Castle for Java versions before 1.85, and LTS and FIPS versions prior to specific updates.
How do I fix CVE-2026-59649?
To fix CVE-2026-59649, upgrade your Bouncy Castle for Java to version 1.85 or later, or update your LTS or FIPS version accordingly.
What does CVE-2026-59649 affect within OpenPGP?
CVE-2026-59649 relates to the OpenPGP user-attribute subpacket length, which can be excessively large due to being bounded only by JVM max memory.
Is there a way to mitigate CVE-2026-59649 without an upgrade?
Mitigating CVE-2026-59649 without an upgrade is difficult; the best approach is to update to a patched version.