A vulnerability categorized as critical has been discovered in Legion of the Bouncy Castle Bouncy Castle for Java FIPS, Bouncy Castle for Java LTS and Bouncy Castle for Java. Affected is an unknown function of the component JSSE Hostname Verifier. The manipulation results in improper access controls.

This vulnerability was named CVE-2026-59638. The attack may be performed from remote. There is no available exploit.