CVE-2026-58062
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Summary
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.66 < 1.85 | affected |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 < 2.73.12 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.0.0 < 2.0.2 | affected |
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.1.0 < 2.1.3 | affected |
Weaknesses
- CWE-295: CWE-295 Improper Certificate Validation
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058062
- https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.