7.5
CVE-2026-58059
- EPSS 0.33%
- Veröffentlicht 03.08.2026 02:41:30
- Zuletzt bearbeitet 02.09.2026 14:31:10
- Erkennungen
Quadratic-time escaping when stringifying X.500 distinguished names
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version < 1.85
Bouncycastle ≫ Bouncy Castle For Java Lts Version <= 2.73.11
Bouncycastle ≫ Fips Java Api Version >= 1.0.0 < 1.0.2.7
Bouncycastle ≫ Fips Java Api Version >= 2.0.0 < 2.0.2
Bouncycastle ≫ Fips Java Api Version >= 2.1.0 < 2.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.255 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| 91579145-5d7b-4cc5-b925-a0262ff19630 | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
|
CWE-407 Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058059