PT-2026-33029 · Bouncy Castle · Bcprov

·

CVE-2026-0636

·

Published

2025-05-19

·

Updated

2026-09-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BC-JAVA versions 1.74 through 1.83
Description Improper neutralization of special elements used in an LDAP query, known as LDAP injection, exists in the BC-JAVA bcprov modules. This issue is associated with the program files LDAPStoreHelper.
Recommendations Update to version 1.84.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10870
CLEANSTART-2026-BK55944
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-KL03760
CLEANSTART-2026-MT41286
CLEANSTART-2026-NE94194
CLEANSTART-2026-NW12954
CLEANSTART-2026-RS65756
CLEANSTART-2026-RU36468
CLEANSTART-2026-SH44648
CLEANSTART-2026-WT54034
CLEANSTART-2026-YY96069
CVE-2026-0636
GHSA-C3FC-8QFF-9HWX
OPENSUSE-SU-2026:10571-1
OPENSUSE-SU-2026:20627-1
RHSA-2026:18054
RHSA-2026:18055
RHSA-2026:53644
SUSE-SU-2026:1639-1
SUSE-SU-2026:21404-1

Affected Products

Bcprov