LDAP Injection Affecting org.bouncycastle:bcprov-debug-jdk14 package, versions [1.74,1.84)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.53% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about LDAP Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGBOUNCYCASTLE-16075249
  • published21 Apr 2026
  • disclosed15 Apr 2026
  • creditPrasanth Sundararajan

Introduced: 15 Apr 2026

CVE-2026-0636  (opens in a new tab)
CWE-90  (opens in a new tab)

How to fix?

Upgrade org.bouncycastle:bcprov-debug-jdk14 to version 1.84 or higher.

Overview

Affected versions of this package are vulnerable to LDAP Injection via the parseDN handling and the LDAP store helpers in X509LDAPCertStoreSpi and LDAPStoreHelper. An attacker can influence LDAP search filters by supplying a crafted X.500 subject or issuer string that is parsed into an unescaped filter value. This lets the attacker alter the directory query used to locate certificates and CRLs, causing the application to retrieve incorrect LDAP entries or fail to find the intended ones, which can break certificate validation and revocation checks.

CVSS Base Scores

version 4.0
version 3.1