Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-58062: Bouncy Castle Java may accept false certificate status

CVE-2026-58062 · published 2 months ago
Summary

The Bouncy Castle libraries for Java can accept a certificate status response that isn’t tied to the specific certificate being checked. This could let an attacker present a forged status and make a certificate appear valid when it is not. Update to the latest versions of the Bouncy Castle Java, LTS, and FIPS packages or apply the vendor’s recommended patches.

What to do
  • Update legion of the bouncy castle inc. bc-java to version 1.85 or later.
  • Update legion of the bouncy castle inc. bc-lts-java to version 2.73.12 or later.
  • Update legion of the bouncy castle inc. bc-fja to version 2.0.2 or later.
  • Update bouncycastle bc-java to version 1.85 or later.
Affected software
Ecosystem VendorProductAffected versions
– legion of the bouncy castle inc. bc-java < 1.85
– legion of the bouncy castle inc. bc-lts-java < 2.73.12
– legion of the bouncy castle inc. bc-fja < 2.0.2
Debian:11 debian bouncycastle All versions
Debian:12 debian bouncycastle All versions
Debian:13 debian bouncycastle All versions
Debian:14 debian bouncycastle All versions
Ubuntu:Pro:16.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:18.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:20.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:22.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:24.04:LTS canonical bouncycastle All versions
Ubuntu:26.04:LTS canonical bouncycastle All versions
– bouncycastle bc-java >= 1.66, < 1.85
cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*
– bouncycastle bouncy_castle_for_java_lts <= 2.73.11
cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*
– bouncycastle fips_java_api < 2.0.2
>= 2.1.0, < 2.1.3
cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:*
Original advisory text
Stapled OCSP response accepted without binding to the checked certificate
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published3 Aug 2026
Updated1 Oct 2026
First seen3 Aug 2026
Track software like this
Free during beta