Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59650

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 7.4

Описание

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

A flaw was found in Bouncy Castle for Java. The software fails to validate Diffie-Hellman peer values during key agreement. A remote attacker can exploit this flaw to compromise cryptographic keys, potentially leading to the decryption of sensitive communications or successful impersonation.

Отчет

This is an Important vulnerability where Bouncy Castle for Java, as used in Red Hat products, fails to validate Diffie-Hellman peer values during key agreement. This flaw allows a remote attacker to compromise cryptographic keys, potentially leading to the decryption of sensitive communications or successful impersonation, due to the low attack complexity and lack of required user interaction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected
Red Hat Enterprise Linux 9resteasyNot affected
Red Hat JBoss Enterprise Application Platform 7bcprov-jdk15onNot affected
Red Hat Single Sign-On 7bcprov-jdk15onNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-325
https://bugzilla.redhat.com/show_bug.cgi?id=2510203bouncycastle: Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS3: 9.1
nvd
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS3: 9.1
debian
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiat ...

CVSS3: 9.1
github
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

suse-cvrf
около 2 месяцев назад

Security update for bouncycastle

7.4 High

CVSS3