Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58062

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 7.4

Описание

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

A flaw was found in Bouncy Castle for Java. A remote attacker could exploit this by presenting a stapled Online Certificate Status Protocol (OCSP) response that is not properly bound to the certificate being checked. This vulnerability allows for a certificate validation bypass, potentially leading to applications accepting invalid or revoked certificates. This could enable man-in-the-middle attacks or unauthorized access.

Отчет

Important: This vulnerability in Bouncy Castle for Java allows a remote attacker to bypass certificate validation. By presenting a stapled OCSP response not properly bound to the certificate being checked, an attacker could cause applications to accept invalid or revoked certificates. This could facilitate man-in-the-middle attacks or unauthorized access in Red Hat products that rely on Bouncy Castle for certificate path validation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Clientsbcprov-jdk15onNot affected
Red Hat Ceph Storage 9cephAffected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected
Red Hat Enterprise Linux 9resteasyNot affected
Red Hat JBoss Enterprise Application Platform 7bcpkix-jdk15onWill not fix
Red Hat JBoss Enterprise Application Platform 7bcprov-jdk15onWill not fix
Red Hat Single Sign-On 7bcpkix-jdk15onAffected
Red Hat Single Sign-On 7bcprov-jdk15onAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2510240org.bouncycastle/bcpkix-jdk15on: org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

CVSS3: 9.1
nvd
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

CVSS3: 9.1
debian
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted ...

CVSS3: 9.1
github
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

suse-cvrf
около 2 месяцев назад

Security update for bouncycastle

7.4 High

CVSS3