CVE-2026-58059

Source
https://cve.org/CVERecord?id=CVE-2026-58059
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58059.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-58059
Downstream
Related
Published
2026-08-03T02:41:30.973Z
Modified
2026-08-14T18:56:23.798074146Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
Quadratic-time escaping when stringifying X.500 distinguished names
Details

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Database specific
{
    "cwe_ids": [
        "CWE-407"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58059.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "fixed": "1.0.2.7"
                },
                {
                    "introduced": "2.0.0"
                },
                {
                    "fixed": "2.0.2"
                },
                {
                    "introduced": "2.1.0"
                },
                {
                    "fixed": "2.1.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "bcorg"
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.85"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
r1rv73
r1rv74
r1rv75
r1rv76
r1rv77
r1rv78
r1rv80
r1rv81
r1rv82
r1rv83
r1rv84
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "222273600143746987005685512304372490880",
                "319204063428353761012336074339418043947",
                "206731246603497995321019478943600372279",
                "61433359492347547604578379136028582276"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "target": {
            "file": "core/src/test/java/org/bouncycastle/asn1/test/X500NameTest.java"
        },
        "id": "CVE-2026-58059-5213e5fa",
        "source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "core/src/test/java/org/bouncycastle/asn1/test/X500NameTest.java",
            "function": "ietfUtilsTest"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "287272836181789225457680162872456768044",
            "length": 87.0
        },
        "source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
        "id": "CVE-2026-58059-ab0804ce",
        "signature_type": "Function"
    },
    {
        "source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/asn1/x500/style/IETFUtils.java",
            "function": "valueToString"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "37998540014217295512214661821265881241",
            "length": 1251.0
        },
        "id": "CVE-2026-58059-ab2ba075",
        "signature_version": "v1",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-58059-ec38eb30",
        "signature_version": "v1",
        "target": {
            "file": "core/src/main/java/org/bouncycastle/asn1/x500/style/IETFUtils.java"
        },
        "deprecated": false,
        "source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
        "digest": {
            "line_hashes": [
                "124301552620111878567884076576528465454",
                "36579054135406476147631717183577972306",
                "254941207732873704741861761964493746193",
                "167712766843365698905380112990159841263",
                "227818824145422898757649279327276436290",
                "262005957509995896053295831910362837541",
                "187080258887802756305625503647033958406",
                "109878138513409945705029513022039554966",
                "336076229697586783052534613432756837059",
                "43848109396705476481187801142838216163",
                "233039401752163705459963093447061193584",
                "9857299006550613672793777475151115745",
                "26560621465350623228007905105915632387",
                "109406414188124409041802949163071399597",
                "174665854050526912998510574245927861796",
                "180387704797628901881813006212748030066",
                "202471176946984662035946211445880403455",
                "198752470078185654891130091122174455900",
                "2531098043601622503549498645785733518",
                "172397210954310268230949611838121246002",
                "85059633920188649949359547037367912230",
                "144921818925751514562730972025758224938",
                "326714444594081853158731748158424971361",
                "221036295170008787974903852758944968507",
                "75407180318704451699303769443305508093",
                "94039341732870811042825618069012052451",
                "152890034545811214017200190546261899343",
                "274572331124479556891609588081588500209",
                "62105435414199897898752435901917307536",
                "54531248605221660420876887114688413356",
                "186134571320226556456791894217385275619",
                "12681867315788374356897613831863703546",
                "9422859815868125619282053418679520701",
                "252165633555238695996603338146540904838",
                "232194827357967547984601337703369737100",
                "292013150979629439892288267054246826206",
                "259460400354662338386565785105473085868",
                "122225948592693884822717630908891163000",
                "156200103911780658076343695720479920139",
                "288472728281979097577206639810214297136",
                "110538260057025719222390581837257904609",
                "159904004132798460745118211210672067740",
                "162992457185731543172945976455217203788",
                "62114009804416069736421318255066945083"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58059.json"
vanir_signatures_modified
"2026-08-12T15:20:46Z"