Name Constraints Bypass Vulnerability in Bouncy Castle for Java
CVE-2026-8763
9.3CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-8763?
The vulnerability in Bouncy Castle for Java allows an attacker to bypass Name Constraints by using a trailing dot within rfc822Name and URI types. This issue affects multiple versions of Bouncy Castle for Java, including its LTS and FIPS variants, making it critical for developers using these libraries to update to secure versions to prevent potential exploits.
Affected Version(s)
BC-FJA all 1.0.0 < 1.0.2.7
BC-FJA all 2.0.0 < 2.0.2
BC-FJA all 2.1.0 < 2.1.3
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Gaynor in collaboration with Claude and Anthropic Research
