CVE-2026-58060

Source
https://cve.org/CVERecord?id=CVE-2026-58060
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58060.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-58060
Downstream
Related
Published
2026-08-03T02:37:43Z
Modified
2026-09-04T14:06:34Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
HSS public-key level count unbounded, enabling huge allocation on verify
Details

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Database specific
{
    "cna_assigner": "bcorg",
    "cwe_ids": [
        "CWE-789"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58060.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.0.0"
                },
                {
                    "fixed": "2.0.2"
                },
                {
                    "introduced": "2.1.0"
                },
                {
                    "fixed": "2.1.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.65"
        },
        {
            "fixed": "1.85"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.73.11"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

Other
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58060.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "62342981262314257328119722246252921619",
                "74824172262263865211192905576817201133",
                "39450435629175718759994301592993793527",
                "338368447039570765068659227004164073949",
                "57314817415941347110348084369654623287",
                "37069736563223782660372052344746258585",
                "54417192076606804309610166928583015638",
                "276581617099108661594598664073345625963"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58060-15f948f7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/pqc/crypto/lms/LMSPublicKeyParameters.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "201128728441098339788989520179942497135",
            "length": 872
        },
        "id": "CVE-2026-58060-37274e59",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/pqc/crypto/lms/LMSPublicKeyParameters.java",
            "function": "getInstance"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "339508408900278061581072579587076478447",
                "265454757191728014977228323213793647652",
                "59667167437988487627477780800697257153",
                "195240878886009788509157257930533004397",
                "203973058591789002520044114989744629573",
                "250528407714043252364981042678929305444",
                "198907207819284185071552644248409188073",
                "288103750843253646859988203599839197824",
                "67134475468710028594688337080822258914",
                "262333839703737210252213389192059682120",
                "27696443536646126984156217234750768790",
                "126273039939476956178551137197193102103",
                "32482707157137789126617498938138192747",
                "183064606854545239143790403607772924404",
                "161419536307059938024509313593712883076",
                "38915734372170941859140795577724594821",
                "268567341669295502965991106831413323903",
                "286730516250420620649368225267663660800",
                "318842891113659837592740675693336408550",
                "142740230641859103252643825404516231452"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58060-5120a919",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/crypto/util/SubjectPublicKeyInfoFactory.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "327803151026591325645512000458345975877",
                "111500998431071496834649745807538545600",
                "28367529512488640050392742727145122595",
                "175167534121244445907202801646815982756"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58060-59ec9277",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/test/java/org/bouncycastle/pqc/crypto/lms/AllTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "122465574733414366563337032438116466918",
                "327796252549196010021452889476452555950",
                "57611377860524808838383051199748443282",
                "108974865597196996879945341328959853598"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58060-626221f8",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/6c9f30b3fdaa3f2140809278caebbffc55920922",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/pqc/crypto/lms/HSSSignature.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "338249586630579316630965747032932439189",
            "length": 622
        },
        "id": "CVE-2026-58060-629321f5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/pqc/crypto/lms/HSSPublicKeyParameters.java",
            "function": "getInstance"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "27547944058640469471689974726050708724",
            "length": 4122
        },
        "id": "CVE-2026-58060-b9d594ab",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/crypto/util/SubjectPublicKeyInfoFactory.java",
            "function": "createSubjectPublicKeyInfo"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "105636198134080001450295534345919400857",
            "length": 952
        },
        "id": "CVE-2026-58060-c96b21dd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/6c9f30b3fdaa3f2140809278caebbffc55920922",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/pqc/crypto/lms/HSSSignature.java",
            "function": "getInstance"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "82809779372472886157934414188928354977",
                "91222355599425165373077572794606018048",
                "168777329919704921719957181689257816658",
                "186654152633532592627464865718879080964",
                "57314817415941347110348084369654623287",
                "37069736563223782660372052344746258585",
                "54417192076606804309610166928583015638",
                "276581617099108661594598664073345625963"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58060-cb649a45",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/pqc/crypto/lms/HSSPublicKeyParameters.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "86426165198103198850492716794102008088",
            "length": 249
        },
        "id": "CVE-2026-58060-ea9f7c7f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/311cabbb6fcead7647fec16681423a4439118276",
        "target": {
            "file": "core/src/test/java/org/bouncycastle/pqc/crypto/lms/AllTests.java",
            "function": "suite"
        }
    }
]
vanir_signatures_modified
"2026-09-04T14:06:34Z"