{"id":"GHSA-9pwp-9qqc-pr26","summary":"Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI","details":"In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).","aliases":["CVE-2026-8763"],"modified":"2026-09-18T17:45:05.341636316Z","published":"2026-08-03T03:31:56Z","database_specific":{"github_reviewed_at":"2026-09-18T17:35:38Z","nvd_published_at":"2026-08-03T01:16:45Z","cwe_ids":["CWE-295"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8763"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"},{"type":"WEB","url":"https://github.com/bcgit/bc-java/wiki/CVE-2026-8763"}],"affected":[{"package":{"name":"org.bouncycastle:bc-fips","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bc-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2.7"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.2.1","1.0.2.3","1.0.2.4","1.0.2.5","1.0.2.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwp-9qqc-pr26/GHSA-9pwp-9qqc-pr26.json"}},{"package":{"name":"org.bouncycastle:bc-fips","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bc-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.2"}]}],"versions":["2.0.0","2.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwp-9qqc-pr26/GHSA-9pwp-9qqc-pr26.json"}},{"package":{"name":"org.bouncycastle:bc-fips","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bc-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.3"}]}],"versions":["2.1.0","2.1.1","2.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwp-9qqc-pr26/GHSA-9pwp-9qqc-pr26.json"}},{"package":{"name":"org.bouncycastle:bcprov-jdk18on","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85"}]}],"versions":["1.71","1.71.1","1.72","1.73","1.74","1.75","1.76","1.77","1.78","1.78.1","1.79","1.80","1.80.2","1.81","1.81.1","1.82","1.83","1.84"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwp-9qqc-pr26/GHSA-9pwp-9qqc-pr26.json"}},{"package":{"name":"org.bouncycastle:bcprov-lts8on","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcprov-lts8on"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.73.12"}]}],"versions":["2.73.0","2.73.1","2.73.10","2.73.11","2.73.2","2.73.3","2.73.4","2.73.5","2.73.6","2.73.7","2.73.8","2.73.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwp-9qqc-pr26/GHSA-9pwp-9qqc-pr26.json"}},{"package":{"name":"org.bouncycastle:bcprov-jdk15to18","ecosystem":"Maven","purl":"pkg:maven/org.bouncycastle/bcprov-jdk15to18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85"}]}],"versions":["1.63","1.64","1.65","1.66","1.67","1.68","1.69","1.70","1.71","1.72","1.73","1.74","1.75","1.76","1.77","1.78","1.78.1","1.79","1.80","1.81","1.82","1.83","1.84"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwp-9qqc-pr26/GHSA-9pwp-9qqc-pr26.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber"}]}