Name Constraints bypass via trailing dot in rfc822Name and URI
Published Aug 3, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.43%
Description
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected products
-
- Version 1.0.0StatusaffectedConstraints<1.0.2.7
- Version 2.0.0StatusaffectedConstraints<2.0.2
- Version 2.1.0StatusaffectedConstraints<2.1.3
- Version
-
- Version 0StatusaffectedConstraints<1.85
- Version
-
- Version 2.73.0StatusaffectedConstraints<2.73.12
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-Fja | unaffected |
| ||||||||||||
| Legion of the Bouncy Castle Inc. | BC-Java | unaffected |
| ||||||||||||
| Legion of the Bouncy Castle Inc. | BC-Lts-Java | unaffected |
|
- < 1.85
- ≤ 2.73.11
- ≥ 1.0.0 · < 1.0.2.7
- ≥ 2.0.0 · < 2.0.2
- ≥ 2.1.0 · < 2.1.3
No data.
Red Hat AMQ Clients
bcprov-jdk15on
Not affected
Red Hat Ceph Storage 9
ceph
Affected
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Not affected
Red Hat Enterprise Linux 9
resteasy
Not affected
Red Hat JBoss Enterprise Application Platform 7
bcpkix-jdk15on
Will not fix
Red Hat JBoss Enterprise Application Platform 7
bcprov-jdk15on
Will not fix
Red Hat Single Sign-On 7
bcpkix-jdk15on
Affected
Red Hat Single Sign-On 7
bcprov-jdk15on
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Clients | bcprov-jdk15on | Not affected | n/a |
| Red Hat Ceph Storage 9 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | bcpkix-jdk15on | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | bcprov-jdk15on | Will not fix | n/a |
| Red Hat Single Sign-On 7 | bcpkix-jdk15on | Affected | n/a |
| Red Hat Single Sign-On 7 | bcprov-jdk15on | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important flaw in Bouncy Castle for Java, a cryptographic library used across various Red Hat products. The vulnerability allows an attacker to bypass Name Constraints in X.509 certificates by manipulating rfc822Name and URI fields with a trailing dot. This bypass could lead to spoofing or unauthorized access, impacting the integrity and confidentiality of communications in affected Red Hat environments.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Aug 3, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00430) | 34.91th | v5 (v2026.06.15) |
| Aug 3, 2026 | 0.33% (0.00331) | 25.66th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-8763 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510198 Issue Tracking
- https://github.com/advisories/GHSA-9pwp-9qqc-pr26 Advisory
- https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558 patch
- https://github.com/bcgit/bc-java/releases/tag/r1rv85v2
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763 vendor-advisoryThird Party AdvisoryPatch
- https://github.com/bcgit/bc-java/wiki/CVE-2026-8763
- https://nvd.nist.gov/vuln/detail/CVE-2026-8763
- https://www.cve.org/CVERecord?id=CVE-2026-8763
Change history (0)
No recorded changes yet.