A vulnerability has been found in Legion of the Bouncy Castle BC-JAVA up to 1.84 and classified as critical. This affects an unknown function of the component MLS hash-ratchet. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2026-59644. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.