In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
{
"cwe_ids": [
"CWE-407"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58059.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.2.7"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.2"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.3"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "bcorg"
}[
{
"deprecated": false,
"digest": {
"line_hashes": [
"222273600143746987005685512304372490880",
"319204063428353761012336074339418043947",
"206731246603497995321019478943600372279",
"61433359492347547604578379136028582276"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "core/src/test/java/org/bouncycastle/asn1/test/X500NameTest.java"
},
"id": "CVE-2026-58059-5213e5fa",
"source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"file": "core/src/test/java/org/bouncycastle/asn1/test/X500NameTest.java",
"function": "ietfUtilsTest"
},
"deprecated": false,
"digest": {
"function_hash": "287272836181789225457680162872456768044",
"length": 87.0
},
"source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
"id": "CVE-2026-58059-ab0804ce",
"signature_type": "Function"
},
{
"source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/x500/style/IETFUtils.java",
"function": "valueToString"
},
"deprecated": false,
"digest": {
"function_hash": "37998540014217295512214661821265881241",
"length": 1251.0
},
"id": "CVE-2026-58059-ab2ba075",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2026-58059-ec38eb30",
"signature_version": "v1",
"target": {
"file": "core/src/main/java/org/bouncycastle/asn1/x500/style/IETFUtils.java"
},
"deprecated": false,
"source": "https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b",
"digest": {
"line_hashes": [
"124301552620111878567884076576528465454",
"36579054135406476147631717183577972306",
"254941207732873704741861761964493746193",
"167712766843365698905380112990159841263",
"227818824145422898757649279327276436290",
"262005957509995896053295831910362837541",
"187080258887802756305625503647033958406",
"109878138513409945705029513022039554966",
"336076229697586783052534613432756837059",
"43848109396705476481187801142838216163",
"233039401752163705459963093447061193584",
"9857299006550613672793777475151115745",
"26560621465350623228007905105915632387",
"109406414188124409041802949163071399597",
"174665854050526912998510574245927861796",
"180387704797628901881813006212748030066",
"202471176946984662035946211445880403455",
"198752470078185654891130091122174455900",
"2531098043601622503549498645785733518",
"172397210954310268230949611838121246002",
"85059633920188649949359547037367912230",
"144921818925751514562730972025758224938",
"326714444594081853158731748158424971361",
"221036295170008787974903852758944968507",
"75407180318704451699303769443305508093",
"94039341732870811042825618069012052451",
"152890034545811214017200190546261899343",
"274572331124479556891609588081588500209",
"62105435414199897898752435901917307536",
"54531248605221660420876887114688413356",
"186134571320226556456791894217385275619",
"12681867315788374356897613831863703546",
"9422859815868125619282053418679520701",
"252165633555238695996603338146540904838",
"232194827357967547984601337703369737100",
"292013150979629439892288267054246826206",
"259460400354662338386565785105473085868",
"122225948592693884822717630908891163000",
"156200103911780658076343695720479920139",
"288472728281979097577206639810214297136",
"110538260057025719222390581837257904609",
"159904004132798460745118211210672067740",
"162992457185731543172945976455217203788",
"62114009804416069736421318255066945083"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58059.json"
"2026-08-12T15:20:46Z"