A vulnerability, which was classified as critical, was found in Legion of the Bouncy Castle Bouncy Castle for Java and Bouncy Castle for Java FIPS. The impacted element is an unknown function of the component OpenPGP. Such manipulation leads to protection mechanism failure.

This vulnerability is documented as CVE-2026-59643. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.