CVE-2026-59638

Published: Ago 03, 2026 Last Modified: Ago 04, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,3
Source: 91579145-5d7b-4cc5-b925-a0262ff19630
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0028
Percentile
0,2th
Updated

EPSS Score Trend (Last 5 Days)

297

Improper Validation of Certificate with Host Mismatch

Incomplete
Common Consequences
Security Scopes Affected:
Access Control Authentication Other
Potential Impacts:
Gain Privileges Or Assume Identity Other
Applicable Platforms
Technologies: Not Technology-Specific, Mobile, Web Based
View CWE Details
https://github.com/bcgit/bc-java/commit/5ac55351cd1a8a7184d41c96a7ee87df0770240a
https://github.com/bcgit/bc-java/commit/799bd15320a6310a447863638aa3df64acef829b
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059638