← Back to CVE List
CVE-2026-8763NVD
Vulnerability Summary
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- Legion of the Bouncy Castle Inc. BC-JAVA < 1.85
- Legion of the Bouncy Castle Inc. BC-LTS-JAVA >= 2.73.0 and < 2.73.12
- Legion of the Bouncy Castle Inc. BC-FJA >= 1.0.0 and < 1.0.2.7
- Legion of the Bouncy Castle Inc. BC-FJA >= 2.0.0 and < 2.0.2
- Legion of the Bouncy Castle Inc. BC-FJA >= 2.1.0 and < 2.1.3
- Legion of the Bouncy Castle Inc. BC-JAVA 1.85
- Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.12
- Legion of the Bouncy Castle Inc. BC-FJA 1.0.2.7
- Legion of the Bouncy Castle Inc. BC-FJA 2.0.2
- Legion of the Bouncy Castle Inc. BC-FJA 2.1.3