CVE-2026-58062

Source
https://cve.org/CVERecord?id=CVE-2026-58062
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58062.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-58062
Downstream
Related
Published
2026-08-03T02:35:28Z
Modified
2026-09-04T08:11:34Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
Stapled OCSP response accepted without binding to the checked certificate
Details

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Database specific
{
    "cna_assigner": "bcorg",
    "cwe_ids": [
        "CWE-295"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58062.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.0.0"
                },
                {
                    "fixed": "2.0.2"
                },
                {
                    "introduced": "2.1.0"
                },
                {
                    "fixed": "2.1.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/bcgit/bc-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-java
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.66"
        },
        {
            "fixed": "1.85"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.73.11"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

Other
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58062.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "201897684713285513176872236298635165058",
            "length": 1085
        },
        "id": "CVE-2026-58062-1b5458f0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java",
            "function": "run"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "83518164794911372392773256857379957025",
            "length": 5843
        },
        "id": "CVE-2026-58062-33883d07",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java",
            "function": "performTest"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "55061591139713379215042378563541110836",
            "length": 303
        },
        "id": "CVE-2026-58062-3e24b098",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/AllTests.java",
            "function": "testOCSP"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "239089667100426456140180899465114636279",
                "128804698380742975336749392795329511339",
                "83570861445916700827216088434598966775",
                "339584110769816970560853131349965396550",
                "254231645591951492893861083077787591889",
                "292629023515034009693798068238131578415",
                "277022237403390559389582531481865470716",
                "171837989124314237902585398507456315926",
                "280602512885775223891864649494833484888",
                "181602420263054775552896284404929724535",
                "24391236156023938547266636299025389966",
                "225048814893734744667905744345760116882",
                "60846986725623212779383974012695723200",
                "234222670033577180518215500006094833087",
                "214536796440660206232583227311552884837",
                "103677506814270047720174383982050134240",
                "320546275918694148486696444077180935807",
                "269431706889483172286494076719076790259",
                "184034747365322075139003704158724943336",
                "45385117590167857757932742321221090815",
                "189455866449379159163922244894196737993",
                "241967966345327397624124968110388509773",
                "60615527518550595880021318918107872658",
                "141095281621813697099662526668928582226",
                "195235115918048892380342781671794066949",
                "75368862656528707667001936286444197148",
                "244574761156235957482271012100055973627",
                "268202984922886845857283377041743534063",
                "240506622554058592010963984981311073472",
                "170660954113767192949624715900617186559",
                "40441755600295000773383367154013637937",
                "213341855314708598078031815863042097716",
                "216485559096835853302900373622276562211",
                "131461410896002995935173889165565734781",
                "140257669004353883469352491616387008750",
                "247346439779208489607159968729194174587",
                "234228667418218693294615744473445826938",
                "307668434784447211553018154311494695309",
                "221206899545957498777111099660494299080",
                "211584446001257586121831560102435299338",
                "287321721407540496973851098073207803600",
                "137107895135596853504259558830425071165",
                "283660268940585314964439787828710750641",
                "256434619456484158928471549077033538954",
                "70913720234052654075977780261869718557",
                "112392901467913820736276455680867893836",
                "5012897796911690822432596260883964806",
                "140756857587248240619449633821221398228",
                "226655786371339510714255466159676397265",
                "278745181959116167127675025751143557873",
                "30140543676859742866080668227515184342",
                "206535705247199733193432529951539494992",
                "9861972274687430266008081918649549498",
                "189251179868927095530347724607463110967",
                "55832577069731687395069002510625127604"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58062-6b104449",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "294945467160412025250651898857626593199",
                "108587633537507210242609878158511307392",
                "148023235822227643606502708305239203404",
                "192188276538996750687261957719605472540"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58062-a5237545",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jce/provider/ProvOcspRevocationChecker.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "102145390578534221747816125466914034730",
            "length": 4021
        },
        "id": "CVE-2026-58062-ae3a9882",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "prov/src/main/java/org/bouncycastle/jce/provider/ProvOcspRevocationChecker.java",
            "function": "check"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "25574631002710345128359112023785251266",
                "284353882245727078433609169116750450244",
                "252716468084647920518316267866302610423",
                "231316090653402449237701251169531593025"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-58062-e0045cce",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
        "target": {
            "file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/AllTests.java"
        }
    }
]
vanir_signatures_modified
"2026-09-04T08:11:34Z"