Summary
The Bouncy Castle public record adds a sustained twenty-nine-CVE Claude-assisted campaign. The issues span certificate and hostname validation, CMS and OpenPGP, TLS, ASN.1 handling, cryptographic state, parsing, and related security boundaries across the Java, LTS, and FIPS lines.
Attribution
This is direct primary-source attribution. Bouncy Castle acts as CNA for the records and names the researcher, Claude, and Anthropic Research. Bugflation counts the exact public identifiers rather than every security fix in the same release series.
References
- Bouncy Castle Java CVE index
- Bouncy Castle: CVE-2026-59638
- CVE record: CVE-2026-58059
- CVE record: CVE-2026-59652
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.