---
id: CVE-2026-59651
title: >-
  In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version
  with 16-bit integrity MAC key
summary: >-
  In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version
  with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java
  LTS before 2.73.12.
severity: high
cwe:
  - CWE-326
  - CWE-1240
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59651'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-59651'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59651.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59651'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510188'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59651'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59651'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-08-03T01:21:08.072Z'
epss: 0.00242
epssPercentile: 0.13623
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 8
  - enterprise_linux 9
  - jboss_enterprise_application_platform 7
  - single_sign_on 7
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
---

## Overview

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat AMQ Broker 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat Enterprise Linux 8, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat OpenStack Platform 13 (Queens), … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59651.json)
