---
id: CVE-2026-59639
title: >-
  In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for
  SignedData with zero signers
summary: >-
  In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for
  SignedData with zero signers. This issue also affects Bouncy Castle for Java
  LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before
  bcpkix-fips 1.0…
severity: high
cwe:
  - CWE-347
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59639'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/99ddc6dcc6782e6a76b0dd587c77e62eb7096ad0
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-59639'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59639.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59639'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510197'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59639'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59639'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-08-03T01:21:07.726Z'
epss: 0.00242
epssPercentile: 0.13695
vendor: Red Hat
product: Red Hat Ceph Storage 9
affected:
  - ceph_storage 9
  - enterprise_linux 8
  - enterprise_linux 9
  - jboss_enterprise_application_platform 7
  - single_sign_on 7
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
---

## Overview

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Ceph Storage 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Ceph Storage 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59639.json)
