Name Constraints Bypass Vulnerability in Bouncy Castle for Java
CVE-2026-8763

9.3CRITICAL

What is CVE-2026-8763?

The vulnerability in Bouncy Castle for Java allows an attacker to bypass Name Constraints by using a trailing dot within rfc822Name and URI types. This issue affects multiple versions of Bouncy Castle for Java, including its LTS and FIPS variants, making it critical for developers using these libraries to update to secure versions to prevent potential exploits.

Affected Version(s)

BC-FJA all 1.0.0 < 1.0.2.7

BC-FJA all 2.0.0 < 2.0.2

BC-FJA all 2.1.0 < 2.1.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor in collaboration with Claude and Anthropic Research
.