PT-2026-33031 · Bouncy Castle · Bc-Java+1
Published
2026-04-15
·
Updated
2026-05-19
·
CVE-2026-5588
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BC-JAVA versions 1.49 through 1.83
BCPKIX-FIPS versions 2.0.6 through 2.0.10
BCPKIX-FIPS versions 2.1.7 through 2.1.10
Description
The PKIX draft CompositeVerifier accepts an empty signature sequence as valid. This issue is associated with the program file
JcaContentVerifierProviderBuilder.Java and involves the use of a broken or risky cryptographic algorithm within the pkix modules.Recommendations
Update BC-JAVA to version 1.84 or later.
Update BCPKIX-FIPS versions 2.0.6 through 2.0.10 to version 2.0.11 or later.
Update BCPKIX-FIPS versions 2.1.7 through 2.1.10 to version 2.1.11 or later.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bc-Java
Bcpkix Fips