---
id: CVE-2026-59642
title: >-
  In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound
  to MAC when authAttrs present
summary: >-
  In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound
  to MAC when authAttrs present. This issue also affects Bouncy Castle for Java
  LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before
  bcpkix-fips …
severity: high
cwe:
  - CWE-354
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59642'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-59642'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59642.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59642'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510204'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59642'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59642'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-08-03T01:21:07.813Z'
epss: 0.00195
epssPercentile: 0.0813
vendor: Red Hat
product: Red Hat Ceph Storage 9
affected:
  - ceph_storage 9
  - enterprise_linux 8
  - enterprise_linux 9
  - jboss_enterprise_application_platform 7
  - single_sign_on 7
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
---

## Overview

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Ceph Storage 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Ceph Storage 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59642.json)
