What is CVE-2026-58062?
This vulnerability in Bouncy Castle for Java allows a stapled OCSP response to be accepted without being bound to the checked certificate. It can lead to improper certificate validation, potentially enabling acceptance of a revoked or malicious certificate. All versions before 1.85, LTS 2.73.12, and specific FIPS releases are affected; upgrading to the patched versions is required.
Azərbaycanca: Bouncy Castle Java kitabxanasında aşkar edilmiş bu zəiflik, stapled OCSP cavabının yoxlanılan sertifikata bağlanmamasına yol verir. Bu, təsirli sertifikat doğrulamasını keçərək mənfi mənşəli sertifikatın qəbuluna səbəb ola bilər. Bouncy Castle 1.85, LTS 2.73.12, FIPS 2.0.2/2.1.3 versiyalarından əvvəlki bütün versiyaları təsirləndirir; yenilənmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Bouncy Castle
FAQ1
What risk does CVE-2026-58062 pose in the Bouncy Castle library?
This vulnerability allows a stapled OCSP response to be accepted without being bound to the checked certificate, leading to improper certificate validation and potential acceptance of a revoked or malicious certificate.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.