{"id":"CVE-2026-58062","summary":"Stapled OCSP response accepted without binding to the checked certificate","details":"In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","modified":"2026-09-04T14:06:33.142794Z","published":"2026-08-03T02:35:28.180Z","related":["CGA-9pvh-942f-phxj","SUSE-SU-2026:23127-1","SUSE-SU-2026:23150-1","SUSE-SU-2026:3559-1","openSUSE-SU-2026:11445-1","openSUSE-SU-2026:21538-1"],"database_specific":{"cna_assigner":"bcorg","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58062.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.0.2"},{"introduced":"2.1.0"},{"fixed":"2.1.3"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-fips/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-lts/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58062.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058062"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58062"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-lts-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"ed1c8899b1b5ce0ff26feda81708c21b011f9750"},{"fixed":"57fbd3c501f7a369f64eda311d6a709fc0bcae84"},{"fixed":"add5f822660f3b2c29fd824e2f4095469c42a1c7"}],"database_specific":{"cpe":"cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.66"},{"fixed":"1.85"}],"source":["CPE_RANGE","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/bcgit/bc-lts-java","events":[{"introduced":"468b5082f3f0971e80bf9edb7029c17b39b9ba0c"},{"fixed":"f101b232c5d3e07ecdd504210a57e43831d6cd65"}],"database_specific":{"cpe":"cpe:2.3:a:bouncycastle:bouncy_castle_for_java_lts:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.73.0"},{"fixed":"2.73.12"},{"introduced":"0"},{"last_affected":"2.73.11"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["r2rv73dot11","r2rv73dot10","r2rv73dot9","r2rv73dot8","r2rv73dot6","r2rv73dot4","r2rv73dot3","r2rv73dot1","r2rv73dot0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58062.json","vanir_signatures_modified":"2026-09-04T14:06:33Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"file":"pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java","function":"run"},"deprecated":false,"digest":{"length":1085,"function_hash":"201897684713285513176872236298635165058"},"id":"CVE-2026-58062-1b5458f0"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"file":"pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java","function":"performTest"},"deprecated":false,"digest":{"function_hash":"83518164794911372392773256857379957025","length":5843},"id":"CVE-2026-58062-33883d07"},{"deprecated":false,"digest":{"function_hash":"55061591139713379215042378563541110836","length":303},"id":"CVE-2026-58062-3e24b098","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"file":"pkix/src/test/java/org/bouncycastle/cert/ocsp/test/AllTests.java","function":"testOCSP"}},{"signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"file":"pkix/src/test/java/org/bouncycastle/cert/ocsp/test/PKIXRevocationTest.java"},"deprecated":false,"digest":{"line_hashes":["239089667100426456140180899465114636279","128804698380742975336749392795329511339","83570861445916700827216088434598966775","339584110769816970560853131349965396550","254231645591951492893861083077787591889","292629023515034009693798068238131578415","277022237403390559389582531481865470716","171837989124314237902585398507456315926","280602512885775223891864649494833484888","181602420263054775552896284404929724535","24391236156023938547266636299025389966","225048814893734744667905744345760116882","60846986725623212779383974012695723200","234222670033577180518215500006094833087","214536796440660206232583227311552884837","103677506814270047720174383982050134240","320546275918694148486696444077180935807","269431706889483172286494076719076790259","184034747365322075139003704158724943336","45385117590167857757932742321221090815","189455866449379159163922244894196737993","241967966345327397624124968110388509773","60615527518550595880021318918107872658","141095281621813697099662526668928582226","195235115918048892380342781671794066949","75368862656528707667001936286444197148","244574761156235957482271012100055973627","268202984922886845857283377041743534063","240506622554058592010963984981311073472","170660954113767192949624715900617186559","40441755600295000773383367154013637937","213341855314708598078031815863042097716","216485559096835853302900373622276562211","131461410896002995935173889165565734781","140257669004353883469352491616387008750","247346439779208489607159968729194174587","234228667418218693294615744473445826938","307668434784447211553018154311494695309","221206899545957498777111099660494299080","211584446001257586121831560102435299338","287321721407540496973851098073207803600","137107895135596853504259558830425071165","283660268940585314964439787828710750641","256434619456484158928471549077033538954","70913720234052654075977780261869718557","112392901467913820736276455680867893836","5012897796911690822432596260883964806","140756857587248240619449633821221398228","226655786371339510714255466159676397265","278745181959116167127675025751143557873","30140543676859742866080668227515184342","206535705247199733193432529951539494992","9861972274687430266008081918649549498","189251179868927095530347724607463110967","55832577069731687395069002510625127604"],"threshold":0.9},"id":"CVE-2026-58062-6b104449","signature_type":"Line"},{"source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"file":"prov/src/main/java/org/bouncycastle/jce/provider/ProvOcspRevocationChecker.java"},"deprecated":false,"digest":{"line_hashes":["294945467160412025250651898857626593199","108587633537507210242609878158511307392","148023235822227643606502708305239203404","192188276538996750687261957719605472540"],"threshold":0.9},"id":"CVE-2026-58062-a5237545","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"102145390578534221747816125466914034730","length":4021},"id":"CVE-2026-58062-ae3a9882","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"function":"check","file":"prov/src/main/java/org/bouncycastle/jce/provider/ProvOcspRevocationChecker.java"}},{"deprecated":false,"digest":{"line_hashes":["25574631002710345128359112023785251266","284353882245727078433609169116750450244","252716468084647920518316267866302610423","231316090653402449237701251169531593025"],"threshold":0.9},"id":"CVE-2026-58062-e0045cce","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/add5f822660f3b2c29fd824e2f4095469c42a1c7","target":{"file":"pkix/src/test/java/org/bouncycastle/cert/ocsp/test/AllTests.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber"}]}