Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-8763: Bouncy Castle Java lets email/URL validation be bypassed
CVE-2026-8763 · published 2 months ago
Summary
The Bouncy Castle libraries for Java can be tricked into accepting email addresses and web links that should be rejected, due to a flaw in how they handle a trailing dot. This can let attackers bypass security checks that rely on these libraries. Upgrade to the latest versions of bc-java, bc-lts-java, and bc-fja, or apply the vendor’s patches as soon as possible.
What to do
- Update org.bouncycastle:bc-fips to version 1.0.2.6-aikido.1.
- Update io.root.org.bouncycastle:bc-fips to version 1.0.2.6-root.io.1.
- Update org.bouncycastle:bcprov-jdk18on to version 1.84-aikido.1.
- Update org.bouncycastle:bcprov-jdk15to18 to version 1.84-aikido.1.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.84-root.io.1.
- Update io.root.org.bouncycastle:bcprov-jdk15to18 to version 1.84-root.io.1.
- Update org.bouncycastle:bc-fips to version 1.0.2.7.
- Update org.bouncycastle:bc-fips to version 2.0.2.
- Update org.bouncycastle:bc-fips to version 2.1.3.
- Update org.bouncycastle:bcprov-jdk18on to version 1.85.
- Update org.bouncycastle:bcprov-lts8on to version 2.73.12.
- Update org.bouncycastle:bcprov-jdk15to18 to version 1.85.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.4.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.4.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.5.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.5.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.7.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.7.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.9.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.9.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.10.
- Update org.bouncycastle:bcprov-jdk15to18 to version 1.68-aikido.2.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.10.
- Update io.root.org.bouncycastle:bcprov-jdk15to18 to version 1.68-root.io.2.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80.2-aikido.2.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80.2-root.io.2.
- Update org.bouncycastle:bcprov-jdk18on to version 1.80-aikido.12.
- Update io.root.org.bouncycastle:bcprov-jdk18on to version 1.80-root.io.12.
- Update legion of the bouncy castle inc. bc-java to version 1.85 or later.
- Update legion of the bouncy castle inc. bc-lts-java to version 2.73.12 or later.
- Update legion of the bouncy castle inc. bc-fja to version 1.0.2.7 or later.
- Update bouncycastle bc-java to version 1.85 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | legion of the bouncy castle inc. | bc-java | < 1.85 |
| – | legion of the bouncy castle inc. | bc-lts-java | < 2.73.12 |
| – | legion of the bouncy castle inc. | bc-fja | < 1.0.2.7 |
| Debian:11 | debian | bouncycastle | All versions |
| Debian:12 | debian | bouncycastle | All versions |
| Debian:13 | debian | bouncycastle | All versions |
| Debian:14 | debian | bouncycastle | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | bouncycastle | All versions |
| Ubuntu:26.04:LTS | canonical | bouncycastle | All versions |
| – | bouncycastle | bc-java |
< 1.85 cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* |
| – | bouncycastle | bouncy_castle_for_java_lts |
<= 2.73.11 cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:* |
| – | bouncycastle | fips_java_api |
>= 1.0.0, < 1.0.2.7 >= 2.0.0, < 2.0.2 >= 2.1.0, < 2.1.3 cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:* |
| Root:Maven | – | org.bouncycastle:bc-fips |
< 1.0.2.6-aikido.1 Fix: upgrade to 1.0.2.6-aikido.1
|
| Root:Maven | – | io.root.org.bouncycastle:bc-fips |
< 1.0.2.6-root.io.1 Fix: upgrade to 1.0.2.6-root.io.1
|
| Root:Maven | – | org.bouncycastle:bcprov-jdk18on |
< 1.84-aikido.1 < 1.80-aikido.4 < 1.80-aikido.5 < 1.80-aikido.7 < 1.80-aikido.9 < 1.80-aikido.10 < 1.80.2-aikido.2 < 1.80-aikido.12 Fix: upgrade to 1.84-aikido.1
|
| Root:Maven | – | org.bouncycastle:bcprov-jdk15to18 |
< 1.84-aikido.1 < 1.68-aikido.2 Fix: upgrade to 1.84-aikido.1
|
| Root:Maven | – | io.root.org.bouncycastle:bcprov-jdk18on |
< 1.84-root.io.1 < 1.80-root.io.4 < 1.80-root.io.5 < 1.80-root.io.7 < 1.80-root.io.9 < 1.80-root.io.10 < 1.80.2-root.io.2 < 1.80-root.io.12 Fix: upgrade to 1.84-root.io.1
|
| Root:Maven | – | io.root.org.bouncycastle:bcprov-jdk15to18 |
< 1.84-root.io.1 < 1.68-root.io.2 Fix: upgrade to 1.84-root.io.1
|
| maven | – | org.bouncycastle:bc-fips |
< 1.0.2.7 >= 2.0.0, < 2.0.2 >= 2.1.0, < 2.1.3 Fix: upgrade to 1.0.2.7
|
| maven | – | org.bouncycastle:bcprov-jdk18on |
< 1.85 Fix: upgrade to 1.85
|
| maven | – | org.bouncycastle:bcprov-lts8on |
< 2.73.12 Fix: upgrade to 2.73.12
|
| maven | – | org.bouncycastle:bcprov-jdk15to18 |
< 1.85 Fix: upgrade to 1.85
|
Original advisory text
CVE-2026-8763 in org.bouncycastle:bc-fips - Patched by Root
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-8763
- https://github.com/bcgit/bc-lts-java Product
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
- https://www.bouncycastle.org/download/bouncy-castle-java-fips/ URL
- https://www.bouncycastle.org/download/bouncy-castle-java-lts/ URL
- https://www.bouncycastle.org/download/bouncy-castle-java/ URL
- https://security-tracker.debian.org/tracker/CVE-2026-8763 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-8763 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-8763 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8763.j... Vendor Advisory
- https://github.com/bcgit/bc-java Product
- https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558
- https://github.com/bcgit/bc-java/wiki/CVE-2026-8763
- https://github.com/bcgit/bc-java/releases/tag/r1rv85v2
- https://github.com/advisories/GHSA-9pwp-9qqc-pr26
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-295Improper Certificate Validation
Timeline
Published3 Aug 2026
Updated2 Oct 2026
First seen3 Aug 2026
Sources
CVE-2026-8763 · NVD
CVE-2026-8763 · MITRE
CVE-2026-8763 · OSV
DEBIAN-CVE-2026-8763 · OSV
UBUNTU-CVE-2026-8763 · OSV
GHSA-9pwp-9qqc-pr26 · GHSA
GHSA-9pwp-9qqc-pr26 · OSV
Track software like this
Free during beta