CVE-2026-58062

Source
https://cve.org/CVERecord?id=CVE-2026-58062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-58062
Downstream
Published
2026-08-03T02:35:28.180Z
Modified
2026-08-05T03:32:17.890397450Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
Summary
Stapled OCSP response accepted without binding to the checked certificate
Details

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

Database specific
{
    "cwe_ids": [
        "CWE-295"
    ],
    "cna_assigner": "bcorg",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58062.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.66"
                },
                {
                    "fixed": "1.85"
                },
                {
                    "introduced": "2.0.0"
                },
                {
                    "fixed": "2.0.2"
                },
                {
                    "introduced": "2.1.0"
                },
                {
                    "fixed": "2.1.3"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/bcgit/bc-lts-java

Affected ranges

Type
GIT
Repo
https://github.com/bcgit/bc-lts-java
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.73.12"
        }
    ]
}

Affected versions

Other
r2rv73dot0
r2rv73dot1
r2rv73dot10
r2rv73dot11
r2rv73dot3
r2rv73dot4
r2rv73dot6
r2rv73dot8
r2rv73dot9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58062.json"