CVE-2026-59651: BKS keystore accepts legacy version with 16-bit integrity MAC key
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bouncy Castle for Java (BC)to a version that resolves this vulnerability.Fixed in 1.85 - Upgrade
Upgrade
Bouncy Castle for Java LTS (BC LTS)to a version that resolves this vulnerability.Fixed in 2.73.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59651?
CVE-2026-59651 has a risk rating of 27, indicating a significant vulnerability.
How do I fix CVE-2026-59651?
To fix CVE-2026-59651, upgrade to Bouncy Castle for Java version 1.85 or Bouncy Castle for Java LTS version 2.73.12 or later.
What software is affected by CVE-2026-59651?
CVE-2026-59651 affects Bouncy Castle for Java versions prior to 1.85 and Bouncy Castle for Java LTS versions prior to 2.73.12.
What type of vulnerability is CVE-2026-59651 classified as?
CVE-2026-59651 is classified as a Weak Encryption vulnerability.
What does CVE-2026-59651 involve regarding BKS keystore functionality?
CVE-2026-59651 involves the BKS keystore accepting a legacy version that uses a 16-bit integrity MAC key, which poses security risks.