CVE-2026-59643

CVE-2026-59643CVE-2026-59643

Description

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

Scoring

Last modified2026-08-03
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.