216.73.216.226

CVE-2026-5588

· Published 15/04/2026 10:16 · Modified 15/04/2026 17:17

Labels: CVE-2026-5588 2026-04-1591579145-5d7b-4cc5-b925-a0262ff19630CVE-2026-5588CWE-327

Essential information

Published
15/04/2026 10:16
Modified
15/04/2026 17:17
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules). PKIX draft CompositeVerifier accepts empty signature sequence as valid. This issue affects BC-JAVA: from 1.49 before 1.84.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
91579145-5d7b-4cc5-b925-a0262ff19630
NVD
View on NVD

Affected products (CPE)

ProductCPE
bc-java / bouncy castle cpe:2.3:a:bc-java:bouncy_castle:1.49-1.84:*:*:*:*:*:*:*

References