CMS verifySignatures returns true for SignedData with zero signers
Published Aug 3, 2026
8.7
HIGHCVSS 4.0
EPSS 0.24%
Description
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected products
-
- Version 1.0.0StatusaffectedConstraints<1.0.12
- Version 2.0.0StatusaffectedConstraints<2.0.12
- Version 2.1.0StatusaffectedConstraints<2.1.12
- Version
-
- Version 0StatusaffectedConstraints<1.85
- Version
-
- Version 2.73.0StatusaffectedConstraints<2.73.12
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-Fja | unaffected |
| ||||||||||||
| Legion of the Bouncy Castle Inc. | BC-Java | unaffected |
| ||||||||||||
| Legion of the Bouncy Castle Inc. | BC-Lts-Java | unaffected |
|
- < 1.85
- < 1.0.12
- ≥ 2.0.7 · < 2.0.12
- ≥ 2.1.8 · < 2.1.12
- ≤ 2.73.11
No data.
Red Hat Ceph Storage 9
ceph
Out of support scope
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Affected
Red Hat Enterprise Linux 9
resteasy
Affected
Red Hat JBoss Enterprise Application Platform 7
bcpkix-jdk15on
Will not fix
Red Hat Single Sign-On 7
bcpkix-jdk15on
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 9 | ceph | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | bcpkix-jdk15on | Will not fix | n/a |
| Red Hat Single Sign-On 7 | bcpkix-jdk15on | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Bouncy Castle for Java is bundled as a cryptographic provider across numerous Red Hat products. The CMS verifySignatures method incorrectly returns true for SignedData containing zero signers, so unsigned content may be treated as validly signed — a cryptographic signature-verification bypass with a high integrity impact. This affects applications that rely on Bouncy Castle CMS to verify signatures.
Red Hat mitigation
Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcpkix-fips 1.0.12/2.0.12/2.1.12) once available for the affected product.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-59639 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510197 Issue Tracking
- https://github.com/bcgit/bc-java/commit/99ddc6dcc6782e6a76b0dd587c77e62eb7096ad0 patch
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059639 vendor-advisoryThird Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59639
- https://nvd.nist.gov/vuln/detail/CVE-2026-59639
- https://www.cve.org/CVERecord?id=CVE-2026-59639
Change history (0)
No recorded changes yet.