CVE-2026-59645: In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.7
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-59645
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-596450.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59645 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Bouncy Castle: Mehrere Schwachstellencert-bund
Recent advisories for In Bouncy Castle
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEU] [hoch] Bouncy Castle: Mehrere Schwachstellencert-bund · 2026-08-03
- unknownCVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a de…nvd · 2026-08-03
- unknownCVE-2026-13586: In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count boun…nvd · 2026-08-03
- unknownCVE-2026-13506: In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard.…nvd · 2026-08-03
- unknownCVE-2026-12860: In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NU…nvd · 2026-08-03
- unknownCVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque len…nvd · 2026-08-03
More from NVD Recent CVEs
- unknownCVE-2026-69249: python-cryptography is a package designed to expose cryptographic primitives and recipes to Py…2026-08-03
- unknownCVE-2026-69248: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-69247: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-67977: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2…2026-08-03
- unknownCVE-2026-67975: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index s…2026-08-03