---
id: CVE-2026-59650
title: >-
  In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates
  unvalidated peer value
summary: >-
  In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates
  unvalidated peer value. This issue also affects Bouncy Castle for Java LTS
  before 2.73.12.
severity: high
cwe:
  - CWE-20
  - CWE-325
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59650'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-59650'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59650.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59650'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510203'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59650'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59650'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-08-03T01:21:08.044Z'
epss: 0.00449
epssPercentile: 0.36264
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - amq_broker 7
  - build_of_apache_camel_for_spring_boot 4
  - build_of_apicurio_registry 3
  - build_of_keycloak
  - fuse 7
  - jboss_enterprise_application_platform 7
  - jboss_enterprise_application_platform 8
  - single_sign_on 7
  - openshift_developer_tools_and_services
  - ansible_automation_platform 2
  - openshift_ai_rhoai
  - openshift_dev_spaces
  - satellite 6
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
---

## Overview

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat AMQ Broker 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat AMQ Broker 7, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59650.json)
