CVE-2026-5588: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Legion of the Bouncy Castle Inc. BC-JAVA
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.
AI Analysis
Technical Summary
The vulnerability CVE-2026-5588 in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix arises because the PKIX draft CompositeVerifier implementation accepts an empty signature sequence as valid. This improper verification allows an attacker to submit a crafted payload with an empty signature sequence that bypasses cryptographic signature checks, undermining the authenticity and integrity of data validated by the CompositeVerifier. The issue affects BC-JAVA versions from 1.67 before 1.80.2, from 1.81 before 1.81.1, and from 1.82 before 1.84; BCPKIX-FIPS from 2.0.6 before 2.0.11 and from 2.1.7 before 2.1.11; and BCPIX-LTS from 2.73.7 before 2.73.11. Red Hat has issued a security advisory and released updates in JBoss Enterprise Application Platform 8.1.6 to fix this vulnerability. The mitigation involves checking for and rejecting empty signature sequences prior to cryptographic validation.
Potential Impact
The vulnerability allows remote attackers to bypass signature verification mechanisms by submitting an empty signature sequence, which the CompositeVerifier incorrectly accepts as valid. This compromises the authenticity and integrity of data, enabling attackers to forge digital signatures and impersonate trusted entities. There is no indication of confidentiality or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
A security update fixing this vulnerability is available and has been released by Red Hat in JBoss Enterprise Application Platform 8.1.6. Users should apply this update to remediate the issue. Additionally, applications should implement checks to ensure that signature sequences are not empty before passing data to the CompositeVerifier. If an empty or null signature sequence is detected, the payload should be explicitly rejected to prevent bypass of signature verification.
CVE-2026-5588: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Legion of the Bouncy Castle Inc. BC-JAVA
Description
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.
CVSS v4.0
Score 6.3medium
Affected software
Legion of the Bouncy Castle Inc.
BC-JAVA
Legion of the Bouncy Castle Inc.
BCPKIX-FIPS
Legion of the Bouncy Castle Inc.
BCPIX-LTS
pkg:maven/org.bouncycastle/bcpkixpkg:maven/org.bouncycastle/bcpkix-fipspkg:maven/org.bouncycastle/bcpkix-ltspkg:github/bcpkixpkg:maven/Legion of the Bouncy Castle Inc./bcpkixRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-5588 in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix arises because the PKIX draft CompositeVerifier implementation accepts an empty signature sequence as valid. This improper verification allows an attacker to submit a crafted payload with an empty signature sequence that bypasses cryptographic signature checks, undermining the authenticity and integrity of data validated by the CompositeVerifier. The issue affects BC-JAVA versions from 1.67 before 1.80.2, from 1.81 before 1.81.1, and from 1.82 before 1.84; BCPKIX-FIPS from 2.0.6 before 2.0.11 and from 2.1.7 before 2.1.11; and BCPIX-LTS from 2.73.7 before 2.73.11. Red Hat has issued a security advisory and released updates in JBoss Enterprise Application Platform 8.1.6 to fix this vulnerability. The mitigation involves checking for and rejecting empty signature sequences prior to cryptographic validation.
Potential Impact
The vulnerability allows remote attackers to bypass signature verification mechanisms by submitting an empty signature sequence, which the CompositeVerifier incorrectly accepts as valid. This compromises the authenticity and integrity of data, enabling attackers to forge digital signatures and impersonate trusted entities. There is no indication of confidentiality or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
A security update fixing this vulnerability is available and has been released by Red Hat in JBoss Enterprise Application Platform 8.1.6. Users should apply this update to remediate the issue. Additionally, applications should implement checks to ensure that signature sequences are not empty before passing data to the CompositeVerifier. If an empty or null signature sequence is detected, the payload should be explicitly rejected to prevent bypass of signature verification.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- bcorg
- Date Reserved
- 2026-04-04T23:50:59.336Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-5588","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18054","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18055","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14276","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14272","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13631","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18059","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17668","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11720","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11721","vendor":"Red Hat"}]
Threat ID: 69df5b0f82d89c981fca1f4c
Added to database: 04/15/2026, 09:31:59 UTC
Last enriched: 08/12/2026, 13:04:56 UTC
Last updated: 09/13/2026, 22:12:42 UTC
Views: 221
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.