Junglewise Threat Intelligence

CVE-2026-0636: Bouncy Castle BC-JAVA LDAP injection in LDAPStoreHelper

CVE-2026-0636 · Severity: medium · CVSS 4 · Published 2026-04-15

Technologies: Legion of the Bouncy Castle Inc. BC-JAVA, org.bouncycastle:bcprov-jdk14 (Maven), org.bouncycastle:bcprov-jdk18on (Maven), org.bouncycastle:bcprov-jdk15to18 (Maven). Vendors: Legion of the Bouncy Castle Inc., Maven.

Executive brief

Bouncy Castle Java (BC-JAVA) is a widely used library for cryptography and certificate processing. A vulnerability in its LDAP certificate store component allows for LDAP injection, which could enable an attacker to manipulate directory queries. If an application uses this library to process un-vetted certificates, it could lead to unauthorized information disclosure from the connected LDAP directory.

Technical details

An LDAP injection vulnerability exists in the LDAPStoreHelper.java file within the org.bouncycastle.x509 package of Bouncy Castle BC-JAVA. The implementation fails to properly sanitize X.500 names (subject or issuer) for LDAP wildcards before incorporating them into directory queries. An attacker providing a specially crafted certificate with wildcard characters can manipulate the resulting LDAP query. This can lead to information disclosure if the API is used in a context that accepts un-vetted certificates. The issue is fixed in versions 1.80.2, 1.81.1, and 1.84 by refactoring DN parsing into a centralized, secure utility class.

Affected products

  • Legion of the Bouncy Castle Inc. BC-JAVA 1.74 to 1.80.1, 1.81, 1.82 to 1.83

Timeline

  • 2026-01-02: patched: Fix committed to repository
  • 2026-04-15: disclosed: Initial vulnerability publication
  • 2026-05-18: advisory: Advisory updated with specific version ranges and technical details

References

Related threats