Hostname Verification Vulnerability in Bouncy Castle for Java
CVE-2026-59638

9.3CRITICAL

What is CVE-2026-59638?

A vulnerability exists in Bouncy Castle for Java where the JSSE hostname verifier is enabled with a CN-fallback by default. This setting, contrary to prior documentation that required an explicit opt-in, presents a potential security risk as it may allow malicious entities to impersonate legitimate hosts. The issue impacts several versions of Bouncy Castle including the non-LTS and LTS versions, as well as FIPS configurations, posing a serious concern for developers relying on secure connections in their applications. Users are encouraged to update to the latest versions to address this flaw.

Affected Version(s)

BC-FJA all 1.0.7 < 1.0.24

BC-FJA all 2.0.0 < 2.0.24

BC-FJA all 2.1.0 < 2.1.24

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor in collaboration with Claude and Anthropic Research
.