{"id":"CVE-2026-58059","summary":"Quadratic-time escaping when stringifying X.500 distinguished names","details":"In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","modified":"2026-08-14T18:56:23.798074146Z","published":"2026-08-03T02:41:30.973Z","related":["SUSE-SU-2026:23127-1","SUSE-SU-2026:23150-1","SUSE-SU-2026:3559-1","openSUSE-SU-2026:11445-1","openSUSE-SU-2026:21538-1"],"database_specific":{"cna_assigner":"bcorg","cwe_ids":["CWE-407"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58059.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.0.2.7"},{"introduced":"2.0.0"},{"fixed":"2.0.2"},{"introduced":"2.1.0"},{"fixed":"2.1.3"}]}]},"references":[{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-fips/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java-lts/"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58059.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9058059"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58059"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-lts-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"0"},{"fixed":"57fbd3c501f7a369f64eda311d6a709fc0bcae84"},{"fixed":"7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.85"}],"source":["DESCRIPTION","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/bcgit/bc-lts-java","events":[{"introduced":"468b5082f3f0971e80bf9edb7029c17b39b9ba0c"},{"fixed":"f101b232c5d3e07ecdd504210a57e43831d6cd65"}],"database_specific":{"extracted_events":[{"introduced":"2.73.0"},{"fixed":"2.73.12"}],"source":"AFFECTED_FIELD"}}],"versions":["r1rv84","r1rv81","r1rv83","r1rv82","r1rv80","r1rv78","r1rv77","r1rv76","r1rv75","r1rv74","r1rv73","r2rv73dot11","r2rv73dot10","r2rv73dot9","r2rv73dot8","r2rv73dot6","r2rv73dot4","r2rv73dot3","r2rv73dot1","r2rv73dot0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58059.json","vanir_signatures_modified":"2026-08-12T15:20:46Z","vanir_signatures":[{"digest":{"line_hashes":["222273600143746987005685512304372490880","319204063428353761012336074339418043947","206731246603497995321019478943600372279","61433359492347547604578379136028582276"],"threshold":0.9},"id":"CVE-2026-58059-5213e5fa","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b","target":{"file":"core/src/test/java/org/bouncycastle/asn1/test/X500NameTest.java"},"deprecated":false},{"source":"https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b","target":{"file":"core/src/test/java/org/bouncycastle/asn1/test/X500NameTest.java","function":"ietfUtilsTest"},"deprecated":false,"digest":{"function_hash":"287272836181789225457680162872456768044","length":87},"id":"CVE-2026-58059-ab0804ce","signature_type":"Function","signature_version":"v1"},{"digest":{"function_hash":"37998540014217295512214661821265881241","length":1251},"id":"CVE-2026-58059-ab2ba075","signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b","target":{"function":"valueToString","file":"core/src/main/java/org/bouncycastle/asn1/x500/style/IETFUtils.java"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/7bf20eea8c1b71a4d3574b75ba20ccf26ffff36b","target":{"file":"core/src/main/java/org/bouncycastle/asn1/x500/style/IETFUtils.java"},"deprecated":false,"digest":{"line_hashes":["124301552620111878567884076576528465454","36579054135406476147631717183577972306","254941207732873704741861761964493746193","167712766843365698905380112990159841263","227818824145422898757649279327276436290","262005957509995896053295831910362837541","187080258887802756305625503647033958406","109878138513409945705029513022039554966","336076229697586783052534613432756837059","43848109396705476481187801142838216163","233039401752163705459963093447061193584","9857299006550613672793777475151115745","26560621465350623228007905105915632387","109406414188124409041802949163071399597","174665854050526912998510574245927861796","180387704797628901881813006212748030066","202471176946984662035946211445880403455","198752470078185654891130091122174455900","2531098043601622503549498645785733518","172397210954310268230949611838121246002","85059633920188649949359547037367912230","144921818925751514562730972025758224938","326714444594081853158731748158424971361","221036295170008787974903852758944968507","75407180318704451699303769443305508093","94039341732870811042825618069012052451","152890034545811214017200190546261899343","274572331124479556891609588081588500209","62105435414199897898752435901917307536","54531248605221660420876887114688413356","186134571320226556456791894217385275619","12681867315788374356897613831863703546","9422859815868125619282053418679520701","252165633555238695996603338146540904838","232194827357967547984601337703369737100","292013150979629439892288267054246826206","259460400354662338386565785105473085868","122225948592693884822717630908891163000","156200103911780658076343695720479920139","288472728281979097577206639810214297136","110538260057025719222390581837257904609","159904004132798460745118211210672067740","162992457185731543172945976455217203788","62114009804416069736421318255066945083"],"threshold":0.9},"id":"CVE-2026-58059-ec38eb30","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber"}]}