Description
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Published: 2026-08-03
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the OpenPGP Argon2 S2K implementation in Bouncy Castle for Java, where the algorithm honours attacker‑chosen memory and passes values. This allows a malicious user to craft messages that require arbitrarily large amounts of memory to decrypt, potentially exhausting system resources. The flaw is classified as CWE‑770 and carries a CVSS score of 6.9, indicating a moderate severity based on memory consumption and availability impact.

Affected Systems

The affected products are the Bouncy Castle for Java libraries, including the standard Java code, the LTS distribution, and the FIPS‑compliant BC‑FJA build. Versions prior to 1.85 for the standard library, before 2.73.12 for the LTS library, and for the FIPS build prior to bcpg‑fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series), and 2.1.13 (2.1.X series) are vulnerable. All three product lines are maintained by the Legion of the Bouncy Castle Inc.

Risk and Exploitability

The exploit requires the ability to supply a crafted OpenPGP message to the vulnerable library. Although the CVE does not provide explicit evidence of remote exploitation, the nature of the flaw suggests that a remote attacker who can inject data into the application could cause high memory usage, leading to denial of service. The EPSS score is < 1%, and the vulnerability is not currently listed in the CISA KEV catalog. The moderate CVSS score indicates a realistic threat, but no public exploits are reported.

Generated by OpenCVE AI on August 4, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Bouncy Castle for Java to version 1.85 or later, or upgrade the LTS build to 2.73.12 or later, and upgrade the FIPS build to bcpg‑fips 1.0.13, 2.0.13 or 2.1.13 respectively.
  • Configure your application environment to enforce a maximum memory limit on OpenPGP Argon2 S2K decryption operations, ensuring that overly large memory requests cannot exhaust resources.
  • Monitor memory usage during OpenPGP processing and enable alerts for abnormal consumption, allowing rapid response if a malicious message attempts to trigger the vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java
Vendors & Products Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 05:30:00 +0000


Mon, 03 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Description In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Title OpenPGP Argon2 S2K honours attacker-chosen memory and passes
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Legion Of The Bouncy Castle Inc. Bc-fja Bc-java Bc-lts-java
cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-08-03T13:34:16.152Z

Reserved: 2026-07-06T07:09:01.524Z

Link: CVE-2026-59648

cve-icon Vulnrichment

Updated: 2026-08-03T13:34:12.417Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-03T01:16:44.993

Modified: 2026-08-04T14:50:12.360

Link: CVE-2026-59648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:00:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling