Impact
The vulnerability is that the PKIXCertPathReviewer in Bouncy Castle for Java did not apply X.509 name‑constraints to the target certificate. Consequently, a certificate chain whose leaf certificate violates a CA‑issued NameConstraints extension could be marked as valid by isValidCertPath, while the standard PKIXCertPathValidator correctly rejects the chain. This flaw represents an improper validation, demonstrated by the discrepancy between the reviewer and the validator. The weakness is identified as CWE‑295.
Affected Systems
Bouncy Castle for Java releases prior to 1.86, the LTS line prior to 2.73.13, and the FIPS line prior to bcpkix‑fips 1.0.13, 2.0.13, and 2.1.13. The affected products, as listed by the CNA, are BC‑FJA, BC‑JAVA, and BC‑LTS‑JAVA.
Risk and Exploitability
The CVSS score of 8.7 categorises the issue as high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no public exploitation yet. The vulnerability requires that an application incorrectly use PKIXCertPathReviewer for authentication instead of the standard PKIXCertPathValidator. The likely attack vector is inferred to be that an application trusting the reviewer's output could accept an unauthorized certificate. The exploitation complexity is low because it relies on a mis‑implementation rather than a network attack.
OpenCVE Enrichment