OpenPGP inline-signature policy failures silently ignored
Published Aug 3, 2026
8.7
HIGHCVSS 4.0
EPSS 0.24%
Description
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
Affected products
-
- Version 2.0.12StatusaffectedConstraints<2.0.13
- Version
-
- Version 1.81StatusaffectedConstraints<1.85
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-Fja | unaffected |
| ||||||
| Legion of the Bouncy Castle Inc. | BC-Java | unaffected |
|
- < 1.85
- < 2.0.13
No data.
Red Hat Enterprise Linux 9
jmc
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | jmc | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has an Important impact. Bouncy Castle for Java's OpenPGP (bcpg) module silently ignores inline-signature policy failures instead of reporting them to the application. When an application processes OpenPGP-signed data with signature policy constraints, policy violations are not enforced or reported. A remote attacker can exploit this by sending OpenPGP-signed data that violates signature policies. The application will process the data as if the signature policy was satisfied, leading to acceptance of maliciously altered or unauthorized data. This affects applications using Bouncy Castle's bcpg module for OpenPGP signature verification with policy enforcement.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-59643 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510206 Issue Tracking
- https://github.com/bcgit/bc-java/commit/d3f8cc408b4a36d28e5a410c93436fe3d0fe726b patch
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059643 vendor-advisoryThird Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59643
- https://nvd.nist.gov/vuln/detail/CVE-2026-59643
- https://www.cve.org/CVERecord?id=CVE-2026-59643
Change history (0)
No recorded changes yet.