What is CVE-2026-59652?
An LDAP filter injection vulnerability has been identified in the legacy jdk1.4 LDAPStoreHelper component of Bouncy Castle for Java prior to version 1.85. This flaw could lead to remote code execution or data leakage, and immediate update to the latest version is strongly advised.
Azərbaycanca: Bouncy Castle for Java kitabxanasının 1.85 versiyasından əvvəlki versiyalarında köhnə jdk1.4 LDAPStoreHelper komponentində LDAP filter injection zəifliyi aşkar edilib. Bu zəiflik uzaqdan kod icrasına və ya məlumat sızmasına səbəb ola bilər, təcili olaraq kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
In which component of the Bouncy Castle for Java library was the CVE-2026-59652 vulnerability discovered?
This vulnerability was discovered in the legacy jdk1.4 LDAPStoreHelper component of the library.
What measure should be taken to mitigate the CVE-2026-59652 vulnerability?
It is strongly advised to immediately update the library to version 1.85 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.