MEDIUM
LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
Published Aug 3, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.29%
Description
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Affected products
-
- Version 0StatusaffectedConstraints<1.85
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-Java | unaffected |
|
- < 1.85
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat products only ship jdk15 / jdk18 based artifacts. This vulnerability affects legacy jdk1.4. Red hat products are not affected by this vulnerability.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2026-59652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510190 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52022 Advisory
- https://github.com/bcgit/bc-java/commit/27c468af54ee6c6af87eab5a3a8468dce17e24a0 patch
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059652 vendor-advisoryThird Party Advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2026-59652
- https://nvd.nist.gov/vuln/detail/CVE-2026-59652
- https://www.cve.org/CVERecord?id=CVE-2026-59652
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner bcorg
Published Aug 3, 2026
Updated Aug 3, 2026
Reserved Jul 6, 2026
Link CVE-2026-59652
CISA Vulnrichment
Updated Aug 3, 2026
ENISA EUVD
EUVD-2026-52022 Assigner bcorg
Published Aug 3, 2026
Updated Aug 3, 2026
Exploited since n/a
Link EUVD-2026-52022