← All CVEs NewScan detects
critical

CVE-2026-8763

Bouncy Castle for Java certificate/signature verification bypasses (X.509 name-constraint bypass, CMS zero-signer accept, RSA PKCS#1 hash truncation) plus unbounded-KDF DoS

Severity
critical
Affected product
Bouncy Castle, Bouncy Castle LTS
Affected versions
Bouncy Castle ≥ 1.0, < 1.85
Affected versions
Bouncy Castle LTS ≥ 2.0, < 2.73.12
Fixed in
Bouncy Castle 1.85
Fixed in
Bouncy Castle LTS 2.73.12
Added to NewScan
2026-08-03
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Bouncy Castle from its response and reports this CVE when the detected version falls inside the affected range below.

ONE row for the whole 2026-08-03 bc-java batch on purpose: every CVE in it is fixed by the same release, so eleven rows would mean eleven findings that all say "upgrade to 1.85" - noise, not coverage. CVE-2026-8763 (9.3, Name Constraints bypass via a trailing dot in rfc822Name/URI - a constrained CA can issue for names it was constrained out of) is the worst and names the row. Also covers CVE-2026-59639 (CMS verifySignatures returns true for SignedData with ZERO signers - a signature check that passes unsigned data), CVE-2026-12860 (RSA PKCS#1 v1.5 verification skips the last two hash bytes on the NULL-omitted path), CVE-2026-59640 (OpenPGP CFB quick-check oracle on symmetric/session-key paths), CVE-2026-59643 (OpenPGP inline-signature policy failures silently ignored), CVE-2026-59652 (LDAP filter injection in the legacy jdk1.4 LDAPStoreHelper), and the attacker-chosen-KDF-cost DoS set CVE-2026-59647 (CRMF/CMP password-MAC iteration count), CVE-2026-59648 (OpenPGP Argon2 S2K memory and passes), CVE-2026-58063 (BCFKS keystore load), CVE-2026-13586 (PKCS#12 MAC / bag decryption) and CVE-2026-15055 (PKCS#8 / PBES2 decryptors). Version-match only: these are library-internal verification flaws reached through the host application's own crypto paths, with no remote oracle a scanner may probe. `ge` 1.0 keeps the row on the mainline series - the LTS line is the separate "Bouncy Castle LTS" key, because its 2.73.x versions sort ABOVE 1.85 and would otherwise read as patched.

COMPONENT VERSION RANGE

NewScan fingerprints Bouncy Castle LTS from its response and reports this CVE when the detected version falls inside the affected range below.

The LTS (bc*-lts8on, 2.73.x) half of the 2026-08-03 bc-java batch - a separate product key rather than a widened range, because an LTS version sorts above the mainline fix and one range covering both would call a patched build vulnerable. Covers the CVEs the advisories name for the LTS line: CVE-2026-8763, CVE-2026-59639, CVE-2026-12860, CVE-2026-59640, CVE-2026-59647, CVE-2026-59648, CVE-2026-58063, CVE-2026-13586, CVE-2026-15055. Deliberately EXCLUDED: CVE-2026-59652 (mainline-only legacy jdk1.4 LDAPStoreHelper) and CVE-2026-59643 (filed against the FIPS bcpg-fips line, not LTS) - under-reporting beats a wrong claim. The FIPS branch (BC-FJA / bcpg-fips) has no row at all: its fixed version is a distinct series the advisory text does not pin precisely enough to gate on. Version-match only, same as the mainline row.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →