CVE-2026-71889
Received Received - Intake

X.509 Name Constraints Bypass in Bouncy Castle

Vulnerability report for CVE-2026-71889, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the end-entity certificate. checkNameConstraints walked the path with a loop bound of index greater than zero, which is the bound the CA-only steps require, but index zero is the target certificate under the standard CertPath ordering, so the permitted and excluded subtree checks of RFC 5280 sec. 6.1.3 (b) and (c) never ran against the leaf's subject DN or its subjectAltName. A chain whose leaf violated a NameConstraints extension imposed by its own issuing CA therefore reported isValidCertPath() true with an empty error list, while CertPathValidator.getInstance("PKIX", "BC"), which shares no code with the reviewer, rejected the identical chain against the identical trust anchor. An application using the reviewer to make the trust decision rather than for diagnostics alongside a real validation accepted a certificate the constrained CA was never authorised to issue. Both copies now check every certificate in the path including the target, waive the sec. 4.2.1.10 self-issued exemption for the final certificate as sec. 6.1.3 requires, and skip the sec. 6.1.4 (g) constraint-accumulation step for the target. This issue also affects Bouncy Castle for Java LTS before 2.73.13, which carries only the org.bouncycastle.pkix.jcajce copy of the reviewer. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
bouncy_castle bouncy_castle_java to 1.86 (exc)
bouncy_castle bouncy_castle_java_lts to 2.73.13 (exc)
bouncy_castle bouncy_castle_java_fips to 2.1.13 (exc)
bouncycastle bouncy_castle to 1.86 (exc)
bouncycastle bouncy_castle_lts to 2.73.13 (exc)
bouncycastle bouncy_castle_fips to 1.0.13 (exc)
bouncycastle bouncy_castle_fips to 2.0.13 (exc)
bouncycastle bouncy_castle_fips to 2.1.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71889 is a flaw in Bouncy Castle Java libraries where the PKIXCertPathReviewer class failed to enforce X.509 name constraints on the end-entity (target) certificate. Due to an off-by-one error, the reviewer skipped checks for the leaf certificate, allowing invalid certificates to pass validation. This bypassed a critical security mechanism meant to restrict certificate issuance.

Detection Guidance

To detect this vulnerability, check the version of Bouncy Castle libraries in use. For Java applications, inspect the JAR files for bcprov-jdk18on, bcpkix-jdk18on, or bcpkix-fips. Compare versions against affected releases: BC before 1.86, BC-LTS before 2.73.13, or BC-FJA before 1.0.13, 2.0.13, 2.1.13. Use commands like 'find / -name "*.jar" -exec grep -l "BouncyCastle" {} \;' to locate libraries.

Impact Analysis

This vulnerability could allow attackers to bypass name constraints in certificates, enabling the use of unauthorized certificates. Applications relying on the flawed reviewer for trust decisions may accept invalid certificates, potentially leading to man-in-the-middle attacks or unauthorized access to sensitive systems.

Compliance Impact

This vulnerability undermines certificate validation, which is critical for secure communications and identity verification. Non-compliance with standards like GDPR or HIPAA could occur if organizations fail to enforce proper certificate constraints, risking data breaches or unauthorized access to protected health or personal information.

Mitigation Strategies
  • Upgrade Bouncy Castle libraries to fixed versions: BC 1.86 or later, BC-LTS 2.73.13 or later, BC-FJA 1.0.13, 2.0.13, or 2.1.13 or later.
  • Review certificate chains validated by applications using Bouncy Castle to ensure name constraints are enforced on end-entity certificates.
  • Replace any custom trust decisions using PKIXCertPathReviewer with standard CertPathValidator for proper validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71889. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart