Intel

AIKIDO-2026-695025

bcmls-jdk18on is vulnerable to Security Vulnerability

Security VulnerabilityCVE-2026-59644 Published Aug 10, 2026

87

High Risk

This Affects:

JAVAbcmls-jdk18on
1.73.0 - 1.84.0
Fixed in 1.85.0
Are you affected? Scan for Free

TL;DR

The MLS hash-ratchet (GroupKeySet) honours an arbitrary 32-bit generation counter supplied by the sender when advancing keys. A peer can force a huge generation jump and trigger excessive ratchet computation or memory use. MLS sessions that process untrusted generation counters are exposed to denial of service. The fix limits acceptable generation-counter advancement.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you process MLS group key ratcheting with peer-supplied generation counters.

Background info

bcmls-jdk18on is vulnerable to Security Vulnerability in versions 1.73.0 - 1.84.0.

How to fix this

Upgrade the org.bouncycastle:bcmls-jdk18on library to the patch version.