CVE-2026-5588

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.
References
Link Resource
https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588
https://access.redhat.com/errata/RHSA-2026:11720
https://access.redhat.com/errata/RHSA-2026:11721
https://access.redhat.com/errata/RHSA-2026:13631
https://access.redhat.com/errata/RHSA-2026:14272
https://access.redhat.com/errata/RHSA-2026:14276
https://access.redhat.com/errata/RHSA-2026:17668
https://access.redhat.com/errata/RHSA-2026:18054
https://access.redhat.com/errata/RHSA-2026:18055
https://access.redhat.com/errata/RHSA-2026:18059
https://access.redhat.com/errata/RHSA-2026:21772
https://access.redhat.com/errata/RHSA-2026:53644
https://access.redhat.com/errata/RHSA-2026:53806
https://access.redhat.com/errata/RHSA-2026:60239
https://access.redhat.com/errata/RHSA-2026:60246
https://access.redhat.com/errata/RHSA-2026:60247
https://access.redhat.com/errata/RHSA-2026:60248
https://access.redhat.com/errata/RHSA-2026:60249
https://access.redhat.com/errata/RHSA-2026:60250
https://access.redhat.com/errata/RHSA-2026:60251
https://access.redhat.com/errata/RHSA-2026:60252
https://access.redhat.com/errata/RHSA-2026:60254
https://access.redhat.com/errata/RHSA-2026:60256
https://access.redhat.com/errata/RHSA-2026:60259
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/security/cve/CVE-2026-5588
https://bugzilla.redhat.com/show_bug.cgi?id=2458634
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5588.json
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-15 10:16

Updated : 2026-09-11 13:18


NVD link : CVE-2026-5588

Mitre link : CVE-2026-5588

CVE.ORG link : CVE-2026-5588


JSON object : View

Products Affected

No product.

CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-347

Improper Verification of Cryptographic Signature