X.509 Name Constraints Bypass Vulnerability in Bouncy Castle for Java
CVE-2026-71889
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71889?
The Bouncy Castle for Java library prior to version 1.86 exhibits a vulnerability where the PKIXCertPathReviewer fails to apply X.509 name constraints to end-entity certificates. The flaw arises because the method for verifying name constraints does not properly assess the target certificate during the validation process, potentially allowing certificates to be accepted even if they violate the issuing CA's constraints. This oversight can lead applications to make unauthorized trust decisions, undermining their security posture. Subsequent updates have addressed this issue by ensuring that all certificates in the validation path, including the target certificate, are appropriately validated against specified constraints.
Affected Version(s)
BC-FJA all 1.0.4 < 1.0.13
BC-FJA all 2.0.0 < 2.0.13
BC-FJA all 2.1.0 < 2.1.13
