CVE-2026-0636

Source
https://cve.org/CVERecord?id=CVE-2026-0636
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-0636.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-0636
Aliases
Downstream
Related
Published
2026-04-15T08:59:12.677Z
Modified
2026-05-20T04:02:34.905262155Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:A/RE:M/U:Amber CVSS Calculator
Summary
LDAP Injection Vulnerability in LDAPStoreHelper.java
Details

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).

This vulnerability is associated with program files LDAPStoreHelper.

This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Database specific
{
    "cna_assigner": "bcorg",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.74"
                },
                {
                    "fixed": "1.80.2"
                },
                {
                    "introduced": "1.81"
                },
                {
                    "fixed": "1.81.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0636.json",
    "cwe_ids": [
        "CWE-90"
    ]
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events

Affected versions

Other
r1rv82
r1rv83

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-0636.json"