Bouncy Castle Java: Name Constraints Bypass via Trailing Dot in rfc822Name/URI ( 1.85, 2.73.12, 2.
CVE-2026-8763 Published on August 3, 2026
Name Constraints bypass via trailing dot in rfc822Name and URI
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Vulnerability Analysis
CVE-2026-8763 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Affected Versions
Legion of the Bouncy Castle Inc. BC-JAVA:- Before 1.85 is affected.
- Version 2.73.0 and below 2.73.12 is affected.
- Version 1.0.0 and below 1.0.2.7 is affected.
- Version 2.0.0 and below 2.0.2 is affected.
- Version 2.1.0 and below 2.1.3 is affected.