Maven: org.bouncycastle:bcmail-fips
CVE-2026-59641
Safety vulnerability ID: SFTY-20260803-93953
Affected versions of the `org.bouncycastle:bcmail-jdk18on` package are vulnerable to Insufficient Verification of Data Authenticity due to reliance on a signer-controlled attribute for certificate validation. The S/MIME validator uses the `signingTime` attribute, which is asserted by the signer and located within the signed data, as the reference point for certificate path validation. An attacker with an expired or revoked certificate can exploit this by selecting a `signingTime` when their certificate was valid, allowing them to produce a message that appears to validate successfully.
Overview
org.bouncycastle:bcmail-jdk18on – Insufficient Verification of Data Authenticity
Advisory
org.bouncycastle:bcmail-jdk18on – Insufficient Verification of Data Authenticity
Affected Package
Also affects
---
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more