Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-8763: Bouncy Castle Java lets email/URL validation be bypassed

CVE-2026-8763 · published 2 months ago
Summary

The Bouncy Castle libraries for Java can be tricked into accepting email addresses and web links that should be rejected, due to a flaw in how they handle a trailing dot. This can let attackers bypass security checks that rely on these libraries. Upgrade to the latest versions of bc-java, bc-lts-java, and bc-fja, or apply the vendor’s patches as soon as possible.

What to do
  • Update org.bouncycastle:bc-fips to version 1.0.2.6-aikido.1.
  • Update io.root.org.bouncycastle:bc-fips to version 1.0.2.6-root.io.1.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.84-aikido.1.
  • Update org.bouncycastle:bcprov-jdk15to18 to version 1.84-aikido.1.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.84-root.io.1.
  • Update io.root.org.bouncycastle:bcprov-jdk15to18 to version 1.84-root.io.1.
  • Update org.bouncycastle:bc-fips to version 1.0.2.7.
  • Update org.bouncycastle:bc-fips to version 2.0.2.
  • Update org.bouncycastle:bc-fips to version 2.1.3.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.85.
  • Update org.bouncycastle:bcprov-lts8on to version 2.73.12.
  • Update org.bouncycastle:bcprov-jdk15to18 to version 1.85.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.4.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.4.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.5.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.5.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.7.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.7.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.9.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.9.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.10.
  • Update org.bouncycastle:bcprov-jdk15to18 to version 1.68-aikido.2.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.10.
  • Update io.root.org.bouncycastle:bcprov-jdk15to18 to version 1.68-root.io.2.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80.2-aikido.2.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80.2-root.io.2.
  • Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.12.
  • Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.12.
  • Update legion of the bouncy castle inc. bc-java to version 1.85 or later.
  • Update legion of the bouncy castle inc. bc-lts-java to version 2.73.12 or later.
  • Update legion of the bouncy castle inc. bc-fja to version 1.0.2.7 or later.
  • Update bouncycastle bc-java to version 1.85 or later.
Affected software
Ecosystem VendorProductAffected versions
– legion of the bouncy castle inc. bc-java < 1.85
– legion of the bouncy castle inc. bc-lts-java < 2.73.12
– legion of the bouncy castle inc. bc-fja < 1.0.2.7
Debian:11 debian bouncycastle All versions
Debian:12 debian bouncycastle All versions
Debian:13 debian bouncycastle All versions
Debian:14 debian bouncycastle All versions
Ubuntu:Pro:16.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:18.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:20.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:22.04:LTS canonical bouncycastle All versions
Ubuntu:Pro:24.04:LTS canonical bouncycastle All versions
Ubuntu:26.04:LTS canonical bouncycastle All versions
– bouncycastle bc-java < 1.85
cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*
– bouncycastle bouncy_castle_for_java_lts <= 2.73.11
cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*
– bouncycastle fips_java_api >= 1.0.0, < 1.0.2.7
>= 2.0.0, < 2.0.2
>= 2.1.0, < 2.1.3
cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:*
Root:Maven – org.bouncycastle:bc-fips < 1.0.2.6-aikido.1
Fix: upgrade to 1.0.2.6-aikido.1
Root:Maven – io.root.org.bouncycastle:bc-fips < 1.0.2.6-root.io.1
Fix: upgrade to 1.0.2.6-root.io.1
Root:Maven – org.bouncycastle:bcprov-jdk18on < 1.84-aikido.1
< 1.80-aikido.4
< 1.80-aikido.5
< 1.80-aikido.7
< 1.80-aikido.9
< 1.80-aikido.10
< 1.80.2-aikido.2
< 1.80-aikido.12
Fix: upgrade to 1.84-aikido.1
Root:Maven – org.bouncycastle:bcprov-jdk15to18 < 1.84-aikido.1
< 1.68-aikido.2
Fix: upgrade to 1.84-aikido.1
Root:Maven – io.root.org.bouncycastle:bcprov-jdk18on < 1.84-root.io.1
< 1.80-root.io.4
< 1.80-root.io.5
< 1.80-root.io.7
< 1.80-root.io.9
< 1.80-root.io.10
< 1.80.2-root.io.2
< 1.80-root.io.12
Fix: upgrade to 1.84-root.io.1
Root:Maven – io.root.org.bouncycastle:bcprov-jdk15to18 < 1.84-root.io.1
< 1.68-root.io.2
Fix: upgrade to 1.84-root.io.1
maven – org.bouncycastle:bc-fips < 1.0.2.7
>= 2.0.0, < 2.0.2
>= 2.1.0, < 2.1.3
Fix: upgrade to 1.0.2.7
maven – org.bouncycastle:bcprov-jdk18on < 1.85
Fix: upgrade to 1.85
maven – org.bouncycastle:bcprov-lts8on < 2.73.12
Fix: upgrade to 2.73.12
maven – org.bouncycastle:bcprov-jdk15to18 < 1.85
Fix: upgrade to 1.85
Original advisory text
CVE-2026-8763 in org.bouncycastle:bc-fips - Patched by Root
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published3 Aug 2026
Updated2 Oct 2026
First seen3 Aug 2026
Track software like this
Free during beta