CVE-2026-8763
Bouncy Castle for Java certificate/signature verification bypasses (X.509 name-constraint bypass, CMS zero-signer accept, RSA PKCS#1 hash truncation) plus unbounded-KDF DoS
- Severity
- critical
- Affected product
- Bouncy Castle, Bouncy Castle LTS
- Affected versions
- Bouncy Castle ≥ 1.0, < 1.85
- Affected versions
- Bouncy Castle LTS ≥ 2.0, < 2.73.12
- Fixed in
- Bouncy Castle 1.85
- Fixed in
- Bouncy Castle LTS 2.73.12
- Added to NewScan
- 2026-08-03
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Bouncy Castle from its response and reports this CVE when the detected version falls inside the affected range below.
ONE row for the whole 2026-08-03 bc-java batch on purpose: every CVE in it is fixed by the same release, so eleven rows would mean eleven findings that all say "upgrade to 1.85" - noise, not coverage. CVE-2026-8763 (9.3, Name Constraints bypass via a trailing dot in rfc822Name/URI - a constrained CA can issue for names it was constrained out of) is the worst and names the row. Also covers CVE-2026-59639 (CMS verifySignatures returns true for SignedData with ZERO signers - a signature check that passes unsigned data), CVE-2026-12860 (RSA PKCS#1 v1.5 verification skips the last two hash bytes on the NULL-omitted path), CVE-2026-59640 (OpenPGP CFB quick-check oracle on symmetric/session-key paths), CVE-2026-59643 (OpenPGP inline-signature policy failures silently ignored), CVE-2026-59652 (LDAP filter injection in the legacy jdk1.4 LDAPStoreHelper), and the attacker-chosen-KDF-cost DoS set CVE-2026-59647 (CRMF/CMP password-MAC iteration count), CVE-2026-59648 (OpenPGP Argon2 S2K memory and passes), CVE-2026-58063 (BCFKS keystore load), CVE-2026-13586 (PKCS#12 MAC / bag decryption) and CVE-2026-15055 (PKCS#8 / PBES2 decryptors). Version-match only: these are library-internal verification flaws reached through the host application's own crypto paths, with no remote oracle a scanner may probe. `ge` 1.0 keeps the row on the mainline series - the LTS line is the separate "Bouncy Castle LTS" key, because its 2.73.x versions sort ABOVE 1.85 and would otherwise read as patched.
COMPONENT VERSION RANGE
NewScan fingerprints Bouncy Castle LTS from its response and reports this CVE when the detected version falls inside the affected range below.
The LTS (bc*-lts8on, 2.73.x) half of the 2026-08-03 bc-java batch - a separate product key rather than a widened range, because an LTS version sorts above the mainline fix and one range covering both would call a patched build vulnerable. Covers the CVEs the advisories name for the LTS line: CVE-2026-8763, CVE-2026-59639, CVE-2026-12860, CVE-2026-59640, CVE-2026-59647, CVE-2026-59648, CVE-2026-58063, CVE-2026-13586, CVE-2026-15055. Deliberately EXCLUDED: CVE-2026-59652 (mainline-only legacy jdk1.4 LDAPStoreHelper) and CVE-2026-59643 (filed against the FIPS bcpg-fips line, not LTS) - under-reporting beats a wrong claim. The FIPS branch (BC-FJA / bcpg-fips) has no row at all: its fixed version is a distinct series the advisory text does not pin precisely enough to gate on. Version-match only, same as the mainline row.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →