Aller au contenu

Fiche vulnérabilité

CVE-2026-58062 : faille critique bouncycastle bc-java (CVSS 9.1)

Description

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
3 août 2026
Dernière mise à jour
2 sept. 2026

Produits concernés

  • bouncycastle bc-java
  • bouncycastle bouncy castle for java lts
  • bouncycastle fips java api

Références

Rechercher une autre vulnérabilité dans la base CVE