9.1
CVE-2026-58062
- EPSS 0.2%
- Veröffentlicht 03.08.2026 02:35:28
- Zuletzt bearbeitet 02.09.2026 14:33:49
- Erkennungen
Stapled OCSP response accepted without binding to the checked certificate
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bouncycastle ≫ Bc-java Version >= 1.66 < 1.85
Bouncycastle ≫ Bouncy Castle For Java Lts Version <= 2.73.11
Bouncycastle ≫ Fips Java Api Version < 2.0.2
Bouncycastle ≫ Fips Java Api Version >= 2.1.0 < 2.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.104 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| 91579145-5d7b-4cc5-b925-a0262ff19630 | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058062