Maven: org.bouncycastle:bcmail-fips

CVE-2026-59641

Safety vulnerability ID: SFTY-20260803-93953

Affected versions of the `org.bouncycastle:bcmail-jdk18on` package are vulnerable to Insufficient Verification of Data Authenticity due to reliance on a signer-controlled attribute for certificate validation. The S/MIME validator uses the `signingTime` attribute, which is asserted by the signer and located within the signed data, as the reference point for certificate path validation. An attacker with an expired or revoked certificate can exploit this by selecting a `signingTime` when their certificate was valid, allowing them to produce a message that appears to validate successfully.

Created at: Sep 10, 2026Updated at: Sep 10, 2026

Overview

org.bouncycastle:bcmail-jdk18on – Insufficient Verification of Data Authenticity

Advisory

org.bouncycastle:bcmail-jdk18on – Insufficient Verification of Data Authenticity

Affected Package

Affecting org.bouncycastle:bcmail-fips package, versions< 1.0.7>= 2.0.5, < 2.0.7>= 2.1.6, < 2.1.7

Also affects

---

How to Fix

Upgradeorg.bouncycastle:bcmail-fipsto1.0.72.0.72.1.7or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more