CVE-2026-59652
published 2026-08-03CVE-2026-59652: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.30%
22.0th percentile
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bouncycastle: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
vendor_redhat·2026-08-03·CVSS 6.9
CVE-2026-59652 [MEDIUM] CWE-90 bouncycastle: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
bouncycastle: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
A flaw was found in Bouncy Castle for Java, specifically within the legacy `jdk1.4 LDAPStoreHelper`. This vulnerability allows for LDAP filter injection, where an attacker could provide specially crafted input. This could lead to unauthorized information disclosure or modification of data from the Lightweight Directory Access Protocol (LDAP) directory.
Statement: Red Hat products only ship jdk15 / jdk18 based artifacts. This vulnerability affects legacy jdk1.4. Red hat products are not affected by this vulnerability.
GHSA
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
ghsa_unreviewed·2026-08-03
CVE-2026-59652 [MEDIUM] CWE-90 In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
VulDB
Legion of the Bouncy Castle BC-JAVA up to 1.84 ldapStoreHelper injection
vuldb·2026-08-03·CVSS 6.9
CVE-2026-59652 [MEDIUM] Legion of the Bouncy Castle BC-JAVA up to 1.84 ldapStoreHelper injection
A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.84. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component ldapStoreHelper. The manipulation results in injection.
This vulnerability is known as CVE-2026-59652. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-08-03
Published