CVE-2026-58062
published 2026-08-03CVE-2026-58062: In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.34%
26.5th percentile
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | >= 1.66 < 1.85 | 1.85 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| bouncycastle | fips_java_api | < 2.0.2 | 2.0.2 |
| bouncycastle | fips_java_api | >= 2.1.0 < 2.1.3 | 2.1.3 |
| debian | ceph | — | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.2 | 2.0.2 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.3 | 2.1.3 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.66 < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java FIPS certificate validation (WID-SEC-2026-2622)
vuldb·2026-08-04·CVSS 9.3
CVE-2026-58062 [CRITICAL] Legion of the Bouncy Castle Bouncy Castle for Java FIPS certificate validation (WID-SEC-2026-2622)
A vulnerability has been found in Legion of the Bouncy Castle Bouncy Castle for Java FIPS, Bouncy Castle for Java LTS and Bouncy Castle for Java and classified as problematic. This vulnerability affects unknown code. This manipulation causes improper certificate validation.
This vulnerability is registered as CVE-2026-58062. Remote exploitation of the attack is possible. No exploit is available.
GHSA
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate.
ghsa_unreviewed·2026-08-03
CVE-2026-58062 [CRITICAL] CWE-295 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate.
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Red Hat
org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
vendor_redhat·2026-08-03·CVSS 9.3
CVE-2026-58062 [CRITICAL] CWE-295 org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
A flaw was found in Bouncy Castle for Java. This vulnerability allows a remote attacker to bypass certificate validation by presenting a manipulated Online Certificate Status Protocol (OCSP) response. The system would accept this invalid response without properly verifying its binding to the checked certificate, which could lead to a failure in authenticating digita
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58062 bouncycastle: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response [fedora-all]
bugzilla·2026-08-19·CVSS 9.3
CVE-2026-58062 [CRITICAL] CVE-2026-58062 bouncycastle: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response [fedora-all]
CVE-2026-58062 bouncycastle: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-58062 bouncycastle: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response [epel-all]
bugzilla·2026-08-19·CVSS 9.3
CVE-2026-58062 [CRITICAL] CVE-2026-58062 bouncycastle: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response [epel-all]
CVE-2026-58062 bouncycastle: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-58062 org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
bugzilla·2026-08-03·CVSS 9.3
CVE-2026-58062 [CRITICAL] CVE-2026-58062 org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
CVE-2026-58062 org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
2026-08-03
Published