CVE-2026-59650: MTI/A0 DH agreement exponentiates unvalidated peer value
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59650?
CVE-2026-59650 has a risk score of 47, indicating a moderate level of severity.
How do I fix CVE-2026-59650?
To fix CVE-2026-59650, upgrade to Bouncy Castle for Java version 1.85 or Bouncy Castle for Java LTS version 2.73.12 or later.
What does CVE-2026-59650 affect?
CVE-2026-59650 affects the Bouncy Castle for Java library prior to version 1.85 and its LTS version before 2.73.12.
What is the main issue with CVE-2026-59650?
The main issue with CVE-2026-59650 is that it allows exponentiation of unvalidated peer values in the MTI/A0 DH agreement.
What is the potential impact of CVE-2026-59650?
The potential impact of CVE-2026-59650 includes security vulnerabilities related to cryptographic operations that could be exploited through unvalidated input.