CVE-2026-58059

Vulnerability Overview

A quadratic-time escaping vulnerability, identified as CVE-2026-58059, has been discovered in Bouncy Castle for Java, a popular cryptographic library used in various applications. This vulnerability affects Bouncy Castle for Java versions before 1.85, as well as Bouncy Castle for Java LTS before 2.73.12 and Bouncy Castle for Java FIPS BC-FJA before bc-fips 1.0.2.7.

Indian businesses using Java-based applications should be aware of this vulnerability and take necessary steps to update their systems. The vulnerability can be exploited when stringifying X.500 distinguished names, potentially leading to Denial-of-Service (DoS) attacks.

Affected Versions

The following versions are affected by this vulnerability:

  • Bouncy Castle for Java before 1.85
  • Bouncy Castle for Java LTS before 2.73.12
  • Bouncy Castle for Java FIPS BC-FJA before bc-fips 1.0.2.7

Indian businesses should update their systems to the latest versions to prevent potential attacks and ensure the security of their applications.

More news Book a Free Demo