云虫漏洞库

CVE-2026-59642 - In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). - 漏洞详情

漏洞编号:CVE-2026-59642

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-59642

CNNVD 编号:-

厂商/产品:bouncycastle / bc-java

影响范围:cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*

CWE:CWE-354

发布/更新时间:2026-08-03 / 2026-08-28

漏洞描述

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

相关链接

相关漏洞

« 返回首页