Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5588

30
FAUCET Score

OVERVIEW CVE-2026-5588 is a use of broken or risky cryptographic algorithm vulnerability affecting the Bouncy Castle cryptographic libraries. Specifically, it impacts BC-JAVA versions 1.67 through 1.83 and BCPKIX-FIPS versions 2.0.6 through 2.0.10 and 2.1.7 through 2.1.10. The flaw is located in the JcaContentVerifierProviderBuilder.java file within the PKIX modules of both libraries. SEVERITY The vulnerability relates to improper use of cryptographic algorithms in content verification processes. While specific CVSS scoring is not available, the FAUCET Risk Score of 44.0 out of 100 indicates a moderate threat level. The cryptographic weakness could potentially allow attackers to bypass signature verification or other cryptographic protections, though the exact attack complexity and prerequisites remain limited in public documentation. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities catalog and its inactive status on threat tracking lists. The extremely low EPSS score of 0.0001 suggests minimal likelihood of exploitation attempts. However, organizations using affected versions of these widely-deployed cryptographic libraries should prioritize updating to patched versions 1.84 or later for BC-JAVA and 2.0.11 or 2.1.11 or later for BCPKIX-FIPS.

Impacted Technologies

VendorProductVersion(s)CPE
Legion Of The Bouncy Castle Inc.BCPKIX-FIPS
>= 2.0.6, < 2.0.11, >= 2.1.7, < 2.1.11CNA affecteddefault unaffected
Legion Of The Bouncy Castle Inc.BCPIX-LTS
>= 2.73.7, < 2.73.11CNA affecteddefault unaffected
Legion Of The Bouncy Castle Inc.BC-JAVA
>= 1.67, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 11th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-jdk18onFixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-jdk15to18Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-jdk15onFixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-jdk14Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-debug-jdk18onFixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-debug-jdk15to18Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpkix-debug-jdk14Fixed in: 1.84

Vendor Advisories (1)

mavenGHSA-wg6q-6289-32hpmedium

Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

Apr 15, 2026

References

access.redhat.com / errata/RHSA-2026:11720
access.redhat.com / errata/RHSA-2026:11721
access.redhat.com / errata/RHSA-2026:13631
access.redhat.com / errata/RHSA-2026:14272
access.redhat.com / errata/RHSA-2026:14276
access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / errata/RHSA-2026:21772
access.redhat.com / security/cve/CVE-2026-5588
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-5588.json
github.com / bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057
github.com / bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588