Vulnerability in Bouncy Castle for Java Affects Multiple Versions
CVE-2026-58062
9.3CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-58062?
In Bouncy Castle for Java versions prior to 1.85, a significant issue exists where Stapled OCSP responses are accepted without proper binding to the respective checked certificate. This flaw also extends to the LTS versions below 2.73.12, as well as the FIPS-compliant versions, specifically bc-fips 2.0.2 and below for the 2.0.X series, and 2.1.3 and below for the 2.1.X series. This vulnerability may expose applications using these versions to certificate validation issues, potentially compromising the integrity of secure communications.
Affected Version(s)
BC-FJA all 2.0.0 < 2.0.2
BC-FJA all 2.1.0 < 2.1.3
BC-JAVA all 1.66 < 1.85
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Gaynor in collaboration with Claude and Anthropic Research
