Skip to main content
EPSS 0.6%top 51%

CVE-2026-5588: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Legion of the Bouncy Castle Inc. BC-JAVA

0
Medium
VulnerabilityCVE-2026-5588cvecve-2026-5588cwe-327gcvecwe-347
Published: 04/15/2026 (04/15/2026, 09:06:15 UTC)
Source: CVE Database V5
Vendor/Project: Legion of the Bouncy Castle Inc.
Product: BC-JAVA

Description

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber

Affected software

Legion of the Bouncy Castle Inc.

BC-JAVA

Affected versions
>=1.67 <1.80.2>=1.81 <1.81.1>=1.82 <1.84

Legion of the Bouncy Castle Inc.

BCPKIX-FIPS

Affected versions
>=2.0.6 <2.0.11>=2.1.7 <2.1.11

Legion of the Bouncy Castle Inc.

BCPIX-LTS

Affected versions
>=2.73.7 <2.73.11
org.bouncycastle/bcpkix
pkg:maven/org.bouncycastle/bcpkix
Affected versions
>=1.67 <1.80.2>=1.81 <1.81.1>=1.82 <1.84
org.bouncycastle/bcpkix-fips
pkg:maven/org.bouncycastle/bcpkix-fips
Affected versions
>=2.0.6 <2.0.11>=2.1.7 <2.1.11
org.bouncycastle/bcpkix-lts
pkg:maven/org.bouncycastle/bcpkix-lts
Affected versions
>=2.73.7 <2.73.11
GitHub Actionsmore threats →cve
bcpkix
pkg:github/bcpkix
Affected versions
>=1.67 <1.80.2>=1.81 <1.81.1>=1.82 <1.84
Legion of the Bouncy Castle Inc./bcpkix
pkg:maven/Legion of the Bouncy Castle Inc./bcpkix
Affected versions
>=2.0.6 <2.0.11>=2.1.7 <2.1.11>=2.73.7 <2.73.11

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 13:04:56 UTC

Technical Analysis

The vulnerability CVE-2026-5588 in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix arises because the PKIX draft CompositeVerifier implementation accepts an empty signature sequence as valid. This improper verification allows an attacker to submit a crafted payload with an empty signature sequence that bypasses cryptographic signature checks, undermining the authenticity and integrity of data validated by the CompositeVerifier. The issue affects BC-JAVA versions from 1.67 before 1.80.2, from 1.81 before 1.81.1, and from 1.82 before 1.84; BCPKIX-FIPS from 2.0.6 before 2.0.11 and from 2.1.7 before 2.1.11; and BCPIX-LTS from 2.73.7 before 2.73.11. Red Hat has issued a security advisory and released updates in JBoss Enterprise Application Platform 8.1.6 to fix this vulnerability. The mitigation involves checking for and rejecting empty signature sequences prior to cryptographic validation.

Potential Impact

The vulnerability allows remote attackers to bypass signature verification mechanisms by submitting an empty signature sequence, which the CompositeVerifier incorrectly accepts as valid. This compromises the authenticity and integrity of data, enabling attackers to forge digital signatures and impersonate trusted entities. There is no indication of confidentiality or availability impact. No known exploits in the wild have been reported.

Mitigation Recommendations

A security update fixing this vulnerability is available and has been released by Red Hat in JBoss Enterprise Application Platform 8.1.6. Users should apply this update to remediate the issue. Additionally, applications should implement checks to ensure that signature sequences are not empty before passing data to the CompositeVerifier. If an empty or null signature sequence is detected, the payload should be explicitly rejected to prevent bypass of signature verification.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
bcorg
Date Reserved
2026-04-04T23:50:59.336Z
Cvss Version
4.0
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-5588","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18054","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18055","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14276","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14272","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13631","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18059","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17668","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11720","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11721","vendor":"Red Hat"}]

Threat ID: 69df5b0f82d89c981fca1f4c

Added to database: 04/15/2026, 09:31:59 UTC

Last enriched: 08/12/2026, 13:04:56 UTC

Last updated: 09/13/2026, 22:12:42 UTC

Views: 221

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses