CVE-2026-8763
published 2026-08-03CVE-2026-8763: In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.43%
36.0th percentile
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.85 | 1.85 |
| bouncycastle | bouncy_castle_for_java_lts | <= 2.73.11 | — |
| bouncycastle | fips_java_api | >= 1.0.0 < 1.0.2.7 | 1.0.2.7 |
| bouncycastle | fips_java_api | >= 2.0.0 < 2.0.2 | 2.0.2 |
| bouncycastle | fips_java_api | >= 2.1.0 < 2.1.3 | 2.1.3 |
| debian | ceph | — | — |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 1.0.0 < 1.0.2.7 | 1.0.2.7 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.0.0 < 2.0.2 | 2.0.2 |
| legion_of_the_bouncy_castle_inc | bc-fja | >= 2.1.0 < 2.1.3 | 2.1.3 |
| legion_of_the_bouncy_castle_inc | bc-java | < 1.85 | 1.85 |
| legion_of_the_bouncy_castle_inc | bc-lts-java | >= 2.73.0 < 2.73.12 | 2.73.12 |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI.
ghsa_unreviewed·2026-08-03
CVE-2026-8763 [CRITICAL] CWE-295 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI.
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
VulDB
Legion of the Bouncy Castle Bouncy Castle for Java up to 2.1.2 Name Constraints input validation
vuldb·2026-08-03·CVSS 9.3
CVE-2026-8763 [CRITICAL] Legion of the Bouncy Castle Bouncy Castle for Java up to 2.1.2 Name Constraints input validation
A vulnerability classified as critical was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS up to 1.84/2.73.11/bc-fips 1.0.2.6/2.0.1/2.1.2. Impacted is an unknown function of the component Name Constraints. The manipulation results in improper input validation.
This vulnerability is cataloged as CVE-2026-8763. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
Red Hat
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
vendor_redhat·2026-08-03·CVSS 9.3
CVE-2026-8763 [CRITICAL] CWE-295 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
A flaw was found in Bouncy Castle for Java. This vulnerability allows an attacker to bypass Name Constraints by using a trailing dot in rfc822Name and URI fields. Name Constraints are security mechanisms used in X.509 certificates to restrict the set of names that a certificate can certify. A successful bypass could lead to spoofing or unauthoriz
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8763 bouncycastle: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [epel-all]
bugzilla·2026-08-19·CVSS 9.3
CVE-2026-8763 [CRITICAL] CVE-2026-8763 bouncycastle: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [epel-all]
CVE-2026-8763 bouncycastle: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-8763 ceph: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [fedora-all]
bugzilla·2026-08-19·CVSS 9.3
CVE-2026-8763 [CRITICAL] CVE-2026-8763 ceph: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [fedora-all]
CVE-2026-8763 ceph: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-8763 bouncycastle: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [fedora-all]
bugzilla·2026-08-19·CVSS 9.3
CVE-2026-8763 [CRITICAL] CVE-2026-8763 bouncycastle: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [fedora-all]
CVE-2026-8763 bouncycastle: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Bugzilla
CVE-2026-8763 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
bugzilla·2026-08-03·CVSS 9.3
CVE-2026-8763 [CRITICAL] CVE-2026-8763 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
CVE-2026-8763 org.bouncycastle/bcprov-jdk15on: org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
2026-08-03
Published