CVE-2026-59650
Severity CVSS v4.0:
CRITICAL
Type:
CWE-20
Input Validation
Publication date:
03/08/2026
Last modified:
04/08/2026
Description
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



