CVE-2026-8763
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.43%
- Percentile among all scored CVEs: 35
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access85 % - Primary impact
T1557Adversary-in-the-Middlecredential access · collection80 % - Secondary impact
T1212Exploitation for Credential Accesscredential access75 %
Vulnerabilidad de elusión de Name Constraints en certificados (CWE-295) accesible remotamente sin autenticación (AV:N/PR:N/UI:N). Permite falsificar certificados de dominios confiables, facilitando ataques MITM y compromiso de credenciales en comunicaciones cifradas.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (3)
CWEs
- CWE-295
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-8763",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-8763",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-03T13:29:15.549114Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "91579145-5d7b-4cc5-b925-a0262ff19630",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "AMBER",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "91579145-5d7b-4cc5-b925-a0262ff19630",
"affectedData": [
{
"repo": "https://github.com/bcgit/bc-java",
"vendor": "Legion of the Bouncy Castle Inc.",
"modules": [
"core"
],
"product": "BC-JAVA",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.85",
"versionType": "maven"
}
],
"platforms": [
"all"
],
"packageURL": "pkg:maven/org.bouncycastle/bcprov-jdk18on",
"packageName": "bcprov",
"programFiles": [
"PKIXNameConstraintValidator"
],
"collectionURL": "https://www.bouncycastle.org/download/bouncy-castle-java/",
"defaultStatus": "unaffected"
},
{
"repo": "https://github.com/bcgit/bc-lts-java",
"vendor": "Legion of the Bouncy Castle Inc.",
"modules": [
"core"
],
"product": "BC-LTS-JAVA",
"versions": [
{
"status": "affected",
"version": "2.73.0",
"lessThan": "2.73.12",
"versionType": "maven"
}
],
"platforms": [
"all"
],
"packageURL": "pkg:maven/org.bouncycastle/bcprov-lts8on",
"packageName": "bcprov-lts8on",
"programFiles": [
"PKIXNameConstraintValidator"
],
"collectionURL": "https://www.bouncycastle.org/download/bouncy-castle-java-lts/",
"defaultStatus": "unaffected"
},
{
"vendor": "Legion of the Bouncy Castle Inc.",
"product": "BC-FJA",
"versions": [
{
"status": "affected",
"version": "1.0.0",
"lessThan": "1.0.2.7",
"versionType": "maven"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.2",
"versionType": "maven"
},
{
"status": "affected",
"version": "2.1.0",
"lessThan": "2.1.3",
"versionType": "maven"
}
],
"platforms": [
"all"
],
"packageURL": "pkg:maven/org.bouncycastle/bc-fips",
"packageName": "bc-fips",
"collectionURL": "https://www.bouncycastle.org/download/bouncy-castle-java-fips/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-03T01:16:45.807",
"references": [
{
"url": "https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558",
"tags": [
"Patch"
],
"source": "91579145-5d7b-4cc5-b925-a0262ff19630"
},
{
"url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763",
"tags": [
"Third Party Advisory",
"Patch"
],
"source": "91579145-5d7b-4cc5-b925-a0262ff19630"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "91579145-5d7b-4cc5-b925-a0262ff19630",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."
}
],
"lastModified": "2026-09-02T14:28:48.940",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6A5663-2E62-44AA-8A64-A3CB0DC8813B",
"versionEndExcluding": "1.85"
},
{
"criteria": "cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5ED4F42-08FF-4642-815D-1ED0C82FDBD2",
"versionEndIncluding": "2.73.11"
},
{
"criteria": "cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDB0974E-66FC-45AB-9F1B-0E80B86A4D06",
"versionEndExcluding": "1.0.2.7",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1C285AC-E2BF-4A23-BCD4-494CB5B2C42D",
"versionEndExcluding": "2.0.2",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF53C833-06C3-4BDC-BEF6-50A8B8A0A47C",
"versionEndExcluding": "2.1.3",
"versionStartIncluding": "2.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "91579145-5d7b-4cc5-b925-a0262ff19630"
}