CVE-2026-8763

NameCVE-2026-8763
DescriptionIn Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bouncycastle (PTS)bullseye1.68-2vulnerable
bookworm1.72-2vulnerable
forky, sid, trixie1.80-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bouncycastlesource(unstable)(unfixed)

Notes

https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
Fixed by: https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558 (r1rv85)

Search for package or bug name: Reporting problems