CVE-2026-59638
published 2026-08-03CVE-2026-59638: In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.21%
11.2th percentile
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bctls-fips | >= 1.0.0 < 1.0.24 | 1.0.24 |
| bouncycastle | bctls-fips | >= 2.0.19 < 2.0.24 | 2.0.24 |
| bouncycastle | bctls-fips | >= 2.1.20 < 2.1.24 | 2.1.24 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.7 < 1.0.24 | 1.0.24 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.24 | 2.0.24 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.24 | 2.1.24 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.61 < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.
ghsa_unreviewed·2026-08-03
CVE-2026-59638 [CRITICAL] CWE-297 In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java FIPS JSSE Hostname Verifier access control
vuldb·2026-08-03·CVSS 9.3
CVE-2026-59638 [CRITICAL] Legion of the Bouncy Castle Bouncy Castle for Java FIPS JSSE Hostname Verifier access control
A vulnerability categorized as critical has been discovered in Legion of the Bouncy Castle Bouncy Castle for Java FIPS, Bouncy Castle for Java LTS and Bouncy Castle for Java. Affected is an unknown function of the component JSSE Hostname Verifier. The manipulation results in improper access controls.
This vulnerability was named CVE-2026-59638. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-03
Published