In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
{
"cna_assigner": "bcorg",
"cwe_ids": [
"CWE-295"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58062.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.2"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.3"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.66"
},
{
"fixed": "1.85"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
{
"cpe": "cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "2.73.0"
},
{
"fixed": "2.73.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.73.11"
}
],
"source": [
"AFFECTED_FIELD",
"CPE_RANGE"
]
}
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58062.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "201897684713285513176872236298635165058",
"length": 1085
},
"id": "CVE-2026-58062-1b5458f0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java",
"function": "run"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "83518164794911372392773256857379957025",
"length": 5843
},
"id": "CVE-2026-58062-33883d07",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java",
"function": "performTest"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "55061591139713379215042378563541110836",
"length": 303
},
"id": "CVE-2026-58062-3e24b098",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/AllTests.java",
"function": "testOCSP"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"239089667100426456140180899465114636279",
"128804698380742975336749392795329511339",
"83570861445916700827216088434598966775",
"339584110769816970560853131349965396550",
"254231645591951492893861083077787591889",
"292629023515034009693798068238131578415",
"277022237403390559389582531481865470716",
"171837989124314237902585398507456315926",
"280602512885775223891864649494833484888",
"181602420263054775552896284404929724535",
"24391236156023938547266636299025389966",
"225048814893734744667905744345760116882",
"60846986725623212779383974012695723200",
"234222670033577180518215500006094833087",
"214536796440660206232583227311552884837",
"103677506814270047720174383982050134240",
"320546275918694148486696444077180935807",
"269431706889483172286494076719076790259",
"184034747365322075139003704158724943336",
"45385117590167857757932742321221090815",
"189455866449379159163922244894196737993",
"241967966345327397624124968110388509773",
"60615527518550595880021318918107872658",
"141095281621813697099662526668928582226",
"195235115918048892380342781671794066949",
"75368862656528707667001936286444197148",
"244574761156235957482271012100055973627",
"268202984922886845857283377041743534063",
"240506622554058592010963984981311073472",
"170660954113767192949624715900617186559",
"40441755600295000773383367154013637937",
"213341855314708598078031815863042097716",
"216485559096835853302900373622276562211",
"131461410896002995935173889165565734781",
"140257669004353883469352491616387008750",
"247346439779208489607159968729194174587",
"234228667418218693294615744473445826938",
"307668434784447211553018154311494695309",
"221206899545957498777111099660494299080",
"211584446001257586121831560102435299338",
"287321721407540496973851098073207803600",
"137107895135596853504259558830425071165",
"283660268940585314964439787828710750641",
"256434619456484158928471549077033538954",
"70913720234052654075977780261869718557",
"112392901467913820736276455680867893836",
"5012897796911690822432596260883964806",
"140756857587248240619449633821221398228",
"226655786371339510714255466159676397265",
"278745181959116167127675025751143557873",
"30140543676859742866080668227515184342",
"206535705247199733193432529951539494992",
"9861972274687430266008081918649549498",
"189251179868927095530347724607463110967",
"55832577069731687395069002510625127604"
],
"threshold": 0.9
},
"id": "CVE-2026-58062-6b104449",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"294945467160412025250651898857626593199",
"108587633537507210242609878158511307392",
"148023235822227643606502708305239203404",
"192188276538996750687261957719605472540"
],
"threshold": 0.9
},
"id": "CVE-2026-58062-a5237545",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jce/provider/ProvOcspRevocationChecker.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "102145390578534221747816125466914034730",
"length": 4021
},
"id": "CVE-2026-58062-ae3a9882",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "prov/src/main/java/org/bouncycastle/jce/provider/ProvOcspRevocationChecker.java",
"function": "check"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"25574631002710345128359112023785251266",
"284353882245727078433609169116750450244",
"252716468084647920518316267866302610423",
"231316090653402449237701251169531593025"
],
"threshold": 0.9
},
"id": "CVE-2026-58062-e0045cce",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7",
"target": {
"file": "pkix/src/test/java/org/bouncycastle/cert/ocsp/test/AllTests.java"
}
}
]
"2026-09-04T08:11:34Z"