Junglewise Threat Intelligence

CVE-2026-59646: Bouncy Castle DTLS handshake buffer overflow

CVE-2026-59646 · Severity: high · CVSS 7.5 · Published 2026-08-03

Technologies: Bouncy Castle for Java. Vendors: Bouncy Castle.

Executive brief

Bouncy Castle is a widely-used cryptographic library that handles secure communications, including DTLS (Datagram TLS) handshakes. A flaw in the DTLS handshake reassembler fails to validate a 24-bit length field, allowing an attacker to trigger a buffer overflow and potentially crash the application or execute arbitrary code on systems using affected versions.

Technical details

The vulnerability exists in the DTLS handshake reassembler component of Bouncy Castle for Java, which does not properly validate a 24-bit length field before allocating memory for buffers. An attacker can craft a malicious DTLS handshake message with an unchecked length value to cause a heap buffer overflow. This requires network access to a service using the affected library, no authentication is required. The flaw affects Bouncy Castle for Java before 1.85, Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (bctls-fips) versions 1.0.x before 1.0.24, 2.0.x before 2.0.24, and 2.1.x before 2.1.24. Patches are available in the fixed versions.

Affected products

  • Bouncy Castle Bouncy Castle for Java before 1.85
  • Bouncy Castle Bouncy Castle for Java LTS before 2.73.12
  • Bouncy Castle Bouncy Castle for Java FIPS (bctls-fips) 1.0.x before 1.0.24, 2.0.x before 2.0.24, 2.1.x before 2.1.24

Timeline

  • 2026-08-03: disclosed

References

Related threats