{"id":"CVE-2026-5588","summary":"PKIX draft CompositeVerifier accepts empty signature sequence as valid.","details":"Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules).\n\n This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.","aliases":["GHSA-wg6q-6289-32hp"],"modified":"2026-07-22T04:18:29.814353Z","published":"2026-04-15T09:06:15.617Z","related":["CGA-x825-vhrp-px34","SUSE-SU-2026:1639-1","SUSE-SU-2026:21404-1","openSUSE-SU-2026:10571-1","openSUSE-SU-2026:20627-1"],"database_specific":{"cna_assigner":"bcorg","cwe_ids":["CWE-327"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5588.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.67"},{"fixed":"1.80.2"},{"introduced":"1.81"},{"fixed":"1.81.1"},{"introduced":"2.0.6"},{"fixed":"2.0.11"},{"introduced":"2.1.7"},{"fixed":"2.1.11"},{"introduced":"2.73.7"},{"fixed":"2.73.11"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://repo1.maven.org/maven2/org/bouncycastle/bcpkix-fips/"},{"type":"WEB","url":"https://repo1.maven.org/maven2/org/bouncycastle/bcpkix-lts8on/"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5588.json"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-fips/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-lts/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:11720"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:11721"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13631"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14272"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14276"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17668"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18054"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18055"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18059"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21772"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-5588"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5588.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5588"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458634"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"de42702b6cda2631e8e3ff94f8458198860b328e"},{"fixed":"d716d7716a452bad283323aefd88ff21eba8deef"},{"fixed":"656bae0dbd9b1521f840521ff786e78749fe3057"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"1.82"},{"fixed":"1.84"}]}}],"versions":["r1rv83","r1rv82"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5588.json","vanir_signatures_modified":"2026-07-22T04:18:29Z","vanir_signatures":[{"id":"CVE-2026-5588-354b64ca","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057","target":{"file":"pkix/src/main/java/org/bouncycastle/operator/jcajce/JcaContentVerifierProviderBuilder.java","function":"verify"},"deprecated":false,"digest":{"function_hash":"222855091362562819139087436604490021676","length":451}},{"deprecated":false,"digest":{"line_hashes":["195072041779407728846445507293731859942","111447235815614183114159254103502889060","214049403967823125182578140389836613978","205485957960853458861834660490184824577","325367435558019576692605075665500416592","274190807444330013775732871391456940972","168595733938754340743487419242459249731","151397956106291740010347875324233069667","247428875901493807338869037122051939823","333505368522881872668353417786611832526","79449088181574300880324120092764681688","163472630575912180158137577239879575933","210497132533335900686461427813305303579","78158255502259906173445256807007075414","45278632145243838879841026035860732390"],"threshold":0.9},"id":"CVE-2026-5588-9440a42c","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057","target":{"file":"pkix/src/main/java/org/bouncycastle/operator/jcajce/JcaContentVerifierProviderBuilder.java"}},{"target":{"file":"pkix/src/test/java/org/bouncycastle/cert/cmp/test/AllTests.java"},"deprecated":false,"digest":{"line_hashes":["217041276731360895071401815325791027039","121793159686678409387150321024900702409","265191345860984232230206669714293572950","44061982173660551198024891974042128743","217660425717098281929499955881301520396","253435022659682000179548963694869760858","281940353486035487745609257374396681969","159224345808173189459649863916214657063","303440293933964609763480098046286176122","61991815139583466080119212861094553780","18982741791709997288508492077570687366","185459824064286038285168690044825935427","46019411460362230410522049503785737509","106365765608315215600937734914792339188","20547304236679235891267564382260628932","1239776702976956858881109987350676651","73336223547507980553341684030052109035","181562786864940163015751014992510761604","7152521962194443742688178841392384045","101859662620377821624943035457026445669","248531360770615191787851092648885741663","318121641897421286232200168188499215422","84042054534499695888245302342112342248","129827583298141220242445221037903555230","62922888309390287123304265571055679898","69128788550044491069442188684119695651","88315533901871054078134188044222926595","175403036190103241214957026027337459078","66947934640405096025158481048462821964","25609771579880306091003331315466146166","22925244393535788334522217938072408501","212755598336200137204222102349184637758","35253791003405634888816731287398596210","157736055580284132952270197802095336135","125165991486398871688403165707521390637","65131249821265226141400618786369904307","133184261007571604576865118075097154525","235721836135163685370022480925381660098","94012174285350827789965683170117322782","252087021071019376087793066660397323876","69086372895359846313899861061156472059","328907598940326406617314613303979306711","260067771255115301067473755972852599582","96706737092926588552603962634248306932","91346593631441833573452146562090204592","149501376098897549045100505419554549495","286720021615432703558488401755298424138","111918562201525327821112874450411579244","51352003979200396862019382282714587358","6819642396373813373928441138368977198","204749684814489594999909431383494345995","218665822757132710488495207252260008133","175403036190103241214957026027337459078","66947934640405096025158481048462821964","167918614757235764290383851353478063311","312625725234423742161014153283359670276","274101784525135783030638738640145332718","208940249390454084744335038139538088116","267434734393846745728560306684212731313","192225386090550442804537486777847578036","58219835566335413025182100299689991038","198623094027861218420937880264273397919","109712275631679709623316375178907527570","8704238080965030671756383158620051717","283927181788073872087625029384853314545","203483902787209259504188935826931828532","59207499357236657519336741493546908477","176522348882337772626309287293208227825","252704527797338911430070760143877970916","186541143043650343252327523295300719222","171136714233568374549747666930790697786","312056746530999412276030886806771973762","153950049869905113799871557343715669169","232207033415264654371851737355636919760","196576948077046156018608544683067158365","121674006182793358646266680912347803601","337469863971824730943532055695322799772","103056310270669910061655115831492789776","217531702233737122711197405868831832003","329718649861871057160601508071328939389","175403036190103241214957026027337459078","66947934640405096025158481048462821964","188681572394993580979139570549124038288","244687581618740485609340401915151267333","255725143802231092650278426976017960782","153829132955054971176374724188743113061","185423585195836089577228445079501117033","88273423447153752865860722099901776837","108170302278321098098954827068705969182","52490111259631874766220935911495342910","329255456697141383286705033229177538050","169877020131267490650361898913756351675","215745221309460770723767470292085039267","116079379551356442860527386793972315224","45828544866169519483741872600573703050","249344400801835319990291647981735887274","47925679924022201950173062022962383128","184588595601707959970367321209127558962"],"threshold":0.9},"id":"CVE-2026-5588-e4aea769","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber"}]}