CVE-2026-71889 | Legion of the Bouncy Castle BC-JAVA/BC-LTS-JAVA/BC-FJA prior 1.86/2.73.13/1.0.13/2.0.13/2.1.13 Certificate Path Reviewer PKIXCertPathReviewer.java isValidCertPath certificate validation

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Legion of the Bouncy Castle BC-JAVA, BC-LTS-JAVA and BC-FJA. Affected by this issue is the function isValidCertPath of the file org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java of the component Certificate Path Reviewer. Performing a manipulation results in improper certificate validation.

This vulnerability is reported as CVE-2026-71889. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More