Description
In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the end-entity certificate. checkNameConstraints walked the path with a loop bound of index greater than zero, which is the bound the CA-only steps require, but index zero is the target certificate under the standard CertPath ordering, so the permitted and excluded subtree checks of RFC 5280 sec. 6.1.3 (b) and (c) never ran against the leaf's subject DN or its subjectAltName. A chain whose leaf violated a NameConstraints extension imposed by its own issuing CA therefore reported isValidCertPath() true with an empty error list, while CertPathValidator.getInstance("PKIX", "BC"), which shares no code with the reviewer, rejected the identical chain against the identical trust anchor. An application using the reviewer to make the trust decision rather than for diagnostics alongside a real validation accepted a certificate the constrained CA was never authorised to issue. Both copies now check every certificate in the path including the target, waive the sec. 4.2.1.10 self-issued exemption for the final certificate as sec. 6.1.3 requires, and skip the sec. 6.1.4 (g) constraint-accumulation step for the target. This issue also affects Bouncy Castle for Java LTS before 2.73.13, which carries only the org.bouncycastle.pkix.jcajce copy of the reviewer. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Published: 2026-10-03
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Certificate validation bypass due to missing name‑constraint enforcement
Action: Apply patch
AI Analysis

Impact

The vulnerability is that the PKIXCertPathReviewer in Bouncy Castle for Java did not apply X.509 name‑constraints to the target certificate. Consequently, a certificate chain whose leaf certificate violates a CA‑issued NameConstraints extension could be marked as valid by isValidCertPath, while the standard PKIXCertPathValidator correctly rejects the chain. This flaw represents an improper validation, demonstrated by the discrepancy between the reviewer and the validator. The weakness is identified as CWE‑295.

Affected Systems

Bouncy Castle for Java releases prior to 1.86, the LTS line prior to 2.73.13, and the FIPS line prior to bcpkix‑fips 1.0.13, 2.0.13, and 2.1.13. The affected products, as listed by the CNA, are BC‑FJA, BC‑JAVA, and BC‑LTS‑JAVA.

Risk and Exploitability

The CVSS score of 8.7 categorises the issue as high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no public exploitation yet. The vulnerability requires that an application incorrectly use PKIXCertPathReviewer for authentication instead of the standard PKIXCertPathValidator. The likely attack vector is inferred to be that an application trusting the reviewer's output could accept an unauthorized certificate. The exploitation complexity is low because it relies on a mis‑implementation rather than a network attack.

Generated by OpenCVE AI on October 3, 2026 at 09:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Bouncy Castle releases (BC‑JAVA ≥1.86, BC‑LTS‑JAVA ≥2.73.13, BC‑FJA ≥1.0.13/2.0.13/2.1.13).
  • Replace any use of PKIXCertPathReviewer for authentication with the standard PKIXCertPathValidator that enforces name constraints.
  • If the patch cannot be applied immediately, restrict PKIXCertPathReviewer to diagnostic use only and ensure the application does not rely on its validity result for trust decisions.

Generated by OpenCVE AI on October 3, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the end-entity certificate. checkNameConstraints walked the path with a loop bound of index greater than zero, which is the bound the CA-only steps require, but index zero is the target certificate under the standard CertPath ordering, so the permitted and excluded subtree checks of RFC 5280 sec. 6.1.3 (b) and (c) never ran against the leaf's subject DN or its subjectAltName. A chain whose leaf violated a NameConstraints extension imposed by its own issuing CA therefore reported isValidCertPath() true with an empty error list, while CertPathValidator.getInstance("PKIX", "BC"), which shares no code with the reviewer, rejected the identical chain against the identical trust anchor. An application using the reviewer to make the trust decision rather than for diagnostics alongside a real validation accepted a certificate the constrained CA was never authorised to issue. Both copies now check every certificate in the path including the target, waive the sec. 4.2.1.10 self-issued exemption for the final certificate as sec. 6.1.3 requires, and skip the sec. 6.1.4 (g) constraint-accumulation step for the target. This issue also affects Bouncy Castle for Java LTS before 2.73.13, which carries only the org.bouncycastle.pkix.jcajce copy of the reviewer. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Title PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-03T08:31:01.178Z

Reserved: 2026-08-08T00:06:07.401Z

Link: CVE-2026-71889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T09:17:05.437

Modified: 2026-10-03T09:17:05.437

Link: CVE-2026-71889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T10:00:14Z

Weaknesses
  • CWE-295

    Improper Certificate Validation