What is CVE-2026-8763?
A vulnerability in Bouncy Castle for Java before version 1.85 allows Name Constraints bypass via a trailing dot in `rfc822Name` and `URI` fields. This issue also affects LTS, FIPS, and other series prior to specified fixed versions. Developers should update to the latest patched library releases.
Azərbaycanca: Bouncy Castle Java kitabxanasında `rfc822Name` və `URI` sahələrində sondakı nöqtə (`trailing dot`) vasitəsilə Ad Məhdudiyyətlərinin (`Name Constraints`) yan keçilməsi zəifliyidir. Bu problem 1.85 versiyasından əvvəlki bir çox buraxılışa, o cümlədən LTS, FIPS seriyalarına təsir göstərir. Tərtibatçılar kitabxananı ən son təhlükəsiz versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: Bouncy Castle
FAQ2
What vulnerability has been discovered in the Bouncy Castle library?
A vulnerability has been discovered in Bouncy Castle for Java that allows bypassing of Name Constraints via a trailing dot in `rfc822Name` and `URI` fields.
Which versions of Bouncy Castle are affected by this vulnerability?
The vulnerability affects releases prior to version 1.85, including the LTS and FIPS series.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.