Improper Certificate Validation Affecting org.bouncycastle:bcpkix-fips package, versions [1.0.4,1.0.13)[2.0.0,2.0.13)[2.1.0,2.1.13)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGBOUNCYCASTLE-20536909
  • published6 Oct 2026
  • disclosed3 Oct 2026
  • creditYu Bao

Introduced: 3 Oct 2026

NewCVE-2026-71889  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade org.bouncycastle:bcpkix-fips to version 1.0.13, 2.0.13, 2.1.13 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation. PKIXCertPathReviewer.checkNameConstraints() in org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer and org.bouncycastle.x509.PKIXCertPathReviewer. An attacker can get a constrained certificate chain accepted by supplying a leaf certificate whose subject DN or subjectAltName violates the issuing CA’s NameConstraints extension. When an application relies on the reviewer’s isValidCertPath() result for trust decisions, it accepts an end-entity certificate that the CA was not authorized to issue, allowing unauthorized certificate acceptance.

CVSS Base Scores

version 4.0
version 3.1