PT-2026-33031 · Bouncy Castle · Bc-Java+1

·

CVE-2026-5588

·

Published

2026-04-05

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BC-JAVA versions 1.49 through 1.83 BCPKIX-FIPS versions 2.0.6 through 2.0.10 BCPKIX-FIPS versions 2.1.7 through 2.1.10
Description The PKIX draft CompositeVerifier accepts an empty signature sequence as valid. This issue is associated with the program file JcaContentVerifierProviderBuilder.Java and involves the use of a broken or risky cryptographic algorithm within the pkix modules.
Recommendations Update BC-JAVA to version 1.84 or later. Update BCPKIX-FIPS versions 2.0.6 through 2.0.10 to version 2.0.11 or later. Update BCPKIX-FIPS versions 2.1.7 through 2.1.10 to version 2.1.11 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10868
CLEANSTART-2026-AV84730
CLEANSTART-2026-BK55944
CLEANSTART-2026-DY69070
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-GX01236
CLEANSTART-2026-IS05941
CLEANSTART-2026-JU62349
CLEANSTART-2026-KL03760
CLEANSTART-2026-KP10590
CLEANSTART-2026-MT41286
CLEANSTART-2026-NE94194
CLEANSTART-2026-PK73499
CLEANSTART-2026-PO27799
CLEANSTART-2026-RS65756
CLEANSTART-2026-RU36468
CLEANSTART-2026-SH44648
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SR31778
CLEANSTART-2026-SV95049
CLEANSTART-2026-TK07726
CLEANSTART-2026-VJ37814
CLEANSTART-2026-VN28553
CLEANSTART-2026-WK99982
CLEANSTART-2026-WT54034
CLEANSTART-2026-YY96069
CVE-2026-5588
GHSA-WG6Q-6289-32HP
OPENSUSE-SU-2026:10571-1
OPENSUSE-SU-2026:20627-1
RHSA-2026:18054
RHSA-2026:18055
RHSA-2026:53644
SUSE-SU-2026:1639-1
SUSE-SU-2026:21404-1

Affected Products

Bc-Java
Bcpkix Fips