CRITICAL9.1
GHSA-9pwp-9qqc-pr26
Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI
Quick fix
GHSA-9pwp-9qqc-pr26 — org.bouncycastle:bc-fips: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.0.2.7</version> for org.bouncycastle:bc-fipsDetails
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.bouncycastle:bc-fips
Introduced in:
0Fixed in: 1.0.2.7Fix
# pom.xml: bump <version>1.0.2.7</version> for org.bouncycastle:bc-fipsMaven/org.bouncycastle:bc-fips
Introduced in:
2.0.0Fixed in: 2.0.2Fix
# pom.xml: bump <version>2.0.2</version> for org.bouncycastle:bc-fipsMaven/org.bouncycastle:bc-fips
Introduced in:
2.1.0Fixed in: 2.1.3Fix
# pom.xml: bump <version>2.1.3</version> for org.bouncycastle:bc-fipsMaven/org.bouncycastle:bcprov-jdk18on
Introduced in:
0Fixed in: 1.85Fix
# pom.xml: bump <version>1.85</version> for org.bouncycastle:bcprov-jdk18onMaven/org.bouncycastle:bcprov-lts8on
Introduced in:
0Fixed in: 2.73.12Fix
# pom.xml: bump <version>2.73.12</version> for org.bouncycastle:bcprov-lts8onMaven/org.bouncycastle:bcprov-jdk15to18
Introduced in:
0Fixed in: 1.85Fix
# pom.xml: bump <version>1.85</version> for org.bouncycastle:bcprov-jdk15to18References
- https://nvd.nist.gov/vuln/detail/CVE-2026-8763[ADVISORY]
- https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558[WEB]
- https://github.com/bcgit/bc-java[PACKAGE]
- https://github.com/bcgit/bc-java/releases/tag/r1rv85v2[WEB]
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763[WEB]
- https://github.com/bcgit/bc-java/wiki/CVE-2026-8763[WEB]