BC-JAVA bcpkix 1.491.83: Empty Signature Vulnerability in PKIX CompositeVerifier
CVE-2026-5588 Published on April 15, 2026

PKIX draft CompositeVerifier accepts empty signature sequence as valid.
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-5588 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Types

Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information. The use of a non-standard algorithm is dangerous because a determined attacker may be able to break the algorithm and compromise whatever data has been protected. Well-known techniques may exist to break the algorithm.

Improper Verification of Cryptographic Signature

The software does not verify, or incorrectly verifies, the cryptographic signature for data.


Products Associated with CVE-2026-5588

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-5588 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Legion of the Bouncy Castle Inc. BC-JAVA: Legion of the Bouncy Castle Inc. BCPKIX-FIPS: Legion of the Bouncy Castle Inc. BCPIX-LTS: Red Hat AMQ Broker 7.12.7: Red Hat AMQ Broker 7.13.5: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14: Red Hat build of Quarkus 3.20.6.SP1: Red Hat build of Quarkus 3.27.3.SP1: Red Hat JBoss Enterprise Application Platform 8.1: Red Hat JBoss Enterprise Application Platform 8.1: Red Hat JBoss Enterprise Application Platform 8.1: Red Hat JBoss Enterprise Application Platform 8.1: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9: Red Hat OpenShift Dev Spaces 3.28: Red Hat OpenShift Dev Spaces 3.28: Red Hat Cryostat 4: Red Hat OpenShift Developer Tools and Services: Red Hat OpenShift Developer Tools and Services: Red Hat OpenShift Developer Tools and Services: Red Hat OpenShift Developer Tools and Services: Red Hat AMQ Broker 7: Red Hat build of Apache Camel 4 for Quarkus 3: Red Hat build of Apicurio Registry 3: Red Hat build of Debezium 3: Red Hat Data Grid 8: Red Hat Data Grid 8: Red Hat Data Grid 8: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 9: Red Hat Fuse 7: Red Hat Fuse 7: Red Hat Fuse 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat Process Automation 7: Red Hat Process Automation 7: Red Hat Satellite 6: Red Hat Satellite 6: Red Hat Single Sign-On 7: Red Hat streams for Apache Kafka 2: Red Hat streams for Apache Kafka 2: Red Hat streams for Apache Kafka 3: Red Hat streams for Apache Kafka 3:

Exploit Probability

EPSS
0.26%
Percentile
17.07%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.