PT-2026-33029 · Bouncy Castle · Bcprov

Prasanth Sundararajan

·

Published

2026-04-15

·

Updated

2026-05-21

·

CVE-2026-0636

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BC-JAVA versions 1.74 through 1.83
Description Improper neutralization of special elements used in an LDAP query, known as LDAP injection, exists in the BC-JAVA bcprov modules. This issue is associated with the program files LDAPStoreHelper.
Recommendations Update to version 1.84.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-0636
GHSA-C3FC-8QFF-9HWX
OPENSUSE-SU-2026:10571-1

Affected Products

Bcprov