CVE-2026-58062
Undergoing Analysis
Undergoing Analysis - In Progress
OCSP Response Validation Flaw in Bouncy Castle Java
Vulnerability report for CVE-2026-58062, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-03
Last updated on: 2026-08-03
Assigner: bcorg
Description
Description
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bouncy_castle | bouncy_castle | to 1.85 (exc) |
| bouncy_castle | bouncy_castle_lts | to 2.73.12 (exc) |
| bouncy_castle | bc_fips | to 2.0.2 (exc) |
| bouncy_castle | bc_fips | to 2.1.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |