目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-59640— OpenPGP 对称密钥路径中 CFB 快速检查预言机制激活漏洞

CVSS 8.7 · High EPSS 0.26% · P18

Possible ATT&CK Techniques 1AI

T1555 · Credentials from Password Stores

Affected Version Matrix 5

ベンダープロダクトVersion Rangeステータス
Legion of the Bouncy Castle Inc.BC-FJA1.0.0< 1.0.13affected
2.0.0< 2.0.13affected
2.1.0< 2.1.13affected
Legion of the Bouncy Castle Inc.BC-JAVA< 1.85affected
Legion of the Bouncy Castle Inc.BC-LTS-JAVA2.73.0< 2.73.12affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-59640の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
OpenPGP CFB quick-check oracle active on symmetric/session-key paths
ソース: CVE Program / CVE List V5
脆弱性説明
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber
ソース: CVE Program / CVE List V5
脆弱性タイプ
通过差异性导致的信息暴露
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Legion of the Bouncy Castle Inc.BC-JAVA 0 ~ 1.85 -
Legion of the Bouncy Castle Inc.BC-LTS-JAVA 2.73.0 ~ 2.73.12 -
Legion of the Bouncy Castle Inc.BC-FJA 1.0.0 ~ 1.0.13 -

II. CVE-2026-59640の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-59640のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-59640 补丁与修复 (1)

CVE-2026-59640 其他参考 (1)

Same Patch Batch · Legion of the Bouncy Castle Inc. · 2026-08-03 · 32 CVEs total

CVE-2026-596389.3 CRITICALJSSE hostname verifier CN-fallback enabled by default despite documented opt-in
CVE-2026-580629.3 CRITICALStapled OCSP response accepted without binding to the checked certificate
CVE-2026-87639.3 CRITICALName Constraints bypass via trailing dot in rfc822Name and URI
CVE-2026-596509.3 CRITICALMTI/A0 DH agreement exponentiates unvalidated peer value
CVE-2026-596428.7 HIGHCMS AuthenticatedData content not bound to MAC when authAttrs present
CVE-2026-128528.7 HIGHMLS wire decoder allocates attacker-declared opaque length before bounds check
CVE-2026-146828.7 HIGHPossible OOM from unbounded up-front allocation on a definite-length read
CVE-2026-128608.7 HIGHRSA PKCS#1 verification skips last two hash bytes in NULL-omitted path
CVE-2026-580618.7 HIGHCCM-family modes write plaintext to caller buffer before tag check
CVE-2026-580598.7 HIGHQuadratic-time escaping when stringifying X.500 distinguished names
CVE-2026-580608.7 HIGHHSS public-key level count unbounded, enabling huge allocation on verify
CVE-2026-128038.7 HIGHKCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
CVE-2026-596458.7 HIGHOER parser recurses without depth limit on self-referential IEEE 1609.2 schema
CVE-2026-596418.7 HIGHS/MIME validator trusts signer-asserted signingTime for path validation
CVE-2026-128168.7 HIGHIESEngine stream-mode MAC forgery via length-dependent KDF split
CVE-2026-128178.7 HIGHOpenPGP AEAD decryption skips final tag on chunk-aligned data
CVE-2026-596438.7 HIGHOpenPGP inline-signature policy failures silently ignored
CVE-2026-596468.7 HIGHDTLS handshake reassembler allocates buffer from unchecked 24-bit length
CVE-2026-596498.7 HIGHOpenPGP user-attribute subpacket length bounded only by JVM max memory
CVE-2026-128028.7 HIGHCMS AuthEnvelopedData fails to enforce tag-length on decryption

Showing 20 of 32 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-59640へのコメント

まだコメントはありません


コメントを残す