BC-JAVA bcpkix 1.491.83: Empty Signature Vulnerability in PKIX CompositeVerifier
CVE-2026-5588 Published on April 15, 2026
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules).
This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java.
This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.
Vulnerability Analysis
CVE-2026-5588 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Types
Use of a Broken or Risky Cryptographic Algorithm
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information. The use of a non-standard algorithm is dangerous because a determined attacker may be able to break the algorithm and compromise whatever data has been protected. Well-known techniques may exist to break the algorithm.
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Products Associated with CVE-2026-5588
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-5588 are published in these products:
Affected Versions
Legion of the Bouncy Castle Inc. BC-JAVA:- Version 1.67 and below 1.80.2 is affected.
- Version 1.81 and below 1.81.1 is affected.
- Version 1.82 and below 1.84 is affected.
- Version 2.0.6 and below 2.0.11 is affected.
- Version 2.1.7 and below 2.1.11 is affected.
- Version 2.73.7 and below 2.73.11 is affected.
- Version 0:1.84.0-1.redhat_00001.1.el8eap and below * is unaffected.
- Version 0:2.40.0-6.redhat_00012.1.el9eap and below * is unaffected.
- Version 0:2.0.5-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:2.0.3-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:1.84.0-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:801.6.0-1.GA_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:1.0.3-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:33.0.0-3.jre_redhat_00004.1.el9eap and below * is unaffected.
- Version 0:3.7.19-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:6.6.48-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:7.2.6-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:2.1.4-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:3.6.2-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:16.1.0-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:4.0.6-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:4.1.132-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:4.1.132-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:3.6.1-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:3.1.12-1.redhat_00001.1.el9eap and below * is unaffected.
- Version 0:2.2.21-5.redhat_00003.1.el9eap and below * is unaffected.
- Version 0:8.1.6-5.GA_redhat_00007.1.el9eap and below * is unaffected.
- Version 0:1.0.1-4.Final_redhat_00002.1.el9eap and below * is unaffected.
- Version 0:2.1.4-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:8.1.1-10.GA_redhat_00017.1.el9eap and below * is unaffected.
- Version 0:2.3.0-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:2.3.0-1.Final_redhat_00001.1.el9eap and below * is unaffected.
- Version 0:3.0.4-5.redhat_00007.1.el9eap and below * is unaffected.
- Version 1779528224 and below * is unaffected.
- Version 1779359423 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.