In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy… (CVE-2026-71889)
Bouncy Castle for Java versions before 1.86 and certain LTS and FIPS versions contain a vulnerability in the PKIXCertPathReviewer component where X.509 name constraints were not applied to the end-entity (leaf) certificate. This caused the validation to incorrectly accept certificate chains with leaf certificates violating name constraints imposed by their issuing CA. The issue has been addressed by updating the reviewer to check every certificate in the path, including the target certificate, and correctly applying the relevant RFC 5280 constraints.
AI Analysis
Technical Summary
The vulnerability in Bouncy Castle for Java prior to version 1.86 (including LTS before 2.73.13 and FIPS versions before bcpkix-fips 1.0.13, 2.0.13, and 2.1.13) involves the PKIXCertPathReviewer class failing to apply X.509 name constraints to the end-entity certificate. The checkNameConstraints method did not evaluate the leaf certificate's subject DN or subjectAltName against permitted and excluded subtrees, allowing a certificate chain with a leaf violating its CA's name constraints to be incorrectly validated as valid by the reviewer. This discrepancy between the reviewer and the CertPathValidator could lead applications relying solely on the reviewer for trust decisions to accept unauthorized certificates. The fix ensures all certificates in the path, including the leaf, are checked according to RFC 5280 requirements.
Potential Impact
Applications using the vulnerable PKIXCertPathReviewer for trust decisions could accept certificate chains with leaf certificates that violate name constraints imposed by their issuing CA. This undermines the trust model and could allow unauthorized certificates to be accepted, potentially enabling man-in-the-middle or impersonation attacks if exploited. However, the standard CertPathValidator implementation was not affected and would reject such chains, limiting the impact to applications relying solely on the flawed reviewer.
Mitigation Recommendations
A fix is available in Bouncy Castle for Java version 1.86 and later, as well as in LTS versions 2.73.13 and later, and FIPS versions bcpkix-fips 1.0.13, 2.0.13, and 2.1.13 and later. Users should upgrade to these fixed versions to ensure proper enforcement of X.509 name constraints on end-entity certificates. No additional mitigation is required if using CertPathValidator or updated versions.
In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy… (CVE-2026-71889)
Description
Bouncy Castle for Java versions before 1.86 and certain LTS and FIPS versions contain a vulnerability in the PKIXCertPathReviewer component where X.509 name constraints were not applied to the end-entity (leaf) certificate. This caused the validation to incorrectly accept certificate chains with leaf certificates violating name constraints imposed by their issuing CA. The issue has been addressed by updating the reviewer to check every certificate in the path, including the target certificate, and correctly applying the relevant RFC 5280 constraints.
CVSS v4.0
Affected software
pkg:maven/org.bouncycastle/bcprov-jdk15onRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Bouncy Castle for Java prior to version 1.86 (including LTS before 2.73.13 and FIPS versions before bcpkix-fips 1.0.13, 2.0.13, and 2.1.13) involves the PKIXCertPathReviewer class failing to apply X.509 name constraints to the end-entity certificate. The checkNameConstraints method did not evaluate the leaf certificate's subject DN or subjectAltName against permitted and excluded subtrees, allowing a certificate chain with a leaf violating its CA's name constraints to be incorrectly validated as valid by the reviewer. This discrepancy between the reviewer and the CertPathValidator could lead applications relying solely on the reviewer for trust decisions to accept unauthorized certificates. The fix ensures all certificates in the path, including the leaf, are checked according to RFC 5280 requirements.
Potential Impact
Applications using the vulnerable PKIXCertPathReviewer for trust decisions could accept certificate chains with leaf certificates that violate name constraints imposed by their issuing CA. This undermines the trust model and could allow unauthorized certificates to be accepted, potentially enabling man-in-the-middle or impersonation attacks if exploited. However, the standard CertPathValidator implementation was not affected and would reject such chains, limiting the impact to applications relying solely on the flawed reviewer.
Mitigation Recommendations
A fix is available in Bouncy Castle for Java version 1.86 and later, as well as in LTS versions 2.73.13 and later, and FIPS versions bcpkix-fips 1.0.13, 2.0.13, and 2.1.13 and later. Users should upgrade to these fixed versions to ensure proper enforcement of X.509 name constraints on end-entity certificates. No additional mitigation is required if using CertPathValidator or updated versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hqqj-v58h-gr7x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71889"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac1397da43b0b3b89d66c85
Added to database: 10/03/2026, 17:21:01 UTC
Last enriched: 10/03/2026, 17:30:09 UTC
Last updated: 10/04/2026, 02:46:06 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.