Vulnerability in Bouncy Castle for Java Affects Multiple Versions
CVE-2026-58062

9.3CRITICAL

What is CVE-2026-58062?

In Bouncy Castle for Java versions prior to 1.85, a significant issue exists where Stapled OCSP responses are accepted without proper binding to the respective checked certificate. This flaw also extends to the LTS versions below 2.73.12, as well as the FIPS-compliant versions, specifically bc-fips 2.0.2 and below for the 2.0.X series, and 2.1.3 and below for the 2.1.X series. This vulnerability may expose applications using these versions to certificate validation issues, potentially compromising the integrity of secure communications.

Affected Version(s)

BC-FJA all 2.0.0 < 2.0.2

BC-FJA all 2.1.0 < 2.1.3

BC-JAVA all 1.66 < 1.85

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor in collaboration with Claude and Anthropic Research
.