CVE-2026-59644None▾ SunlitIn Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.3%
In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77399Medium· 6.5icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python
CVE-2026-81880Medium· 5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset
CVE-2026-81872Medium· 6.3OpenTelemetry-Go is the Go implementation of OpenTelemetry
CVE-2026-77357NoneMesop is a Python-based UI framework that allows users to build web applications
CVE-2026-16497High· 7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration
CVE-2026-84311Mediumpypdf is a free and open-source pure-python PDF library