Intel

AIKIDO-2026-45740

bcprov-jdk15on is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2026-71889 Published Sep 30, 2026

85

High Risk

This Affects:

JAVAbcprov-jdk15on
1.46 - 1.70
Are you affected? Scan for Free

TL;DR

The legacy org.bouncycastle.x509.PKIXCertPathReviewer skips X.509 name-constraint checks for the target certificate and can report a prohibited leaf certificate as valid. The fix applies name constraints at path index zero while preserving target-specific RFC behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use org.bouncycastle.x509.PKIXCertPathReviewer as the trust decision for certificate paths constrained by permitted or excluded names.

Background info

bcprov-jdk15on is vulnerable to Improper Certificate Validation in versions 1.46 - 1.70.

How to fix this

Migrate the bcprov-jdk15on dependency to bcprov-jdk18on 1.86 or later, or to bcprov-jdk15to18 1.86 or later if you cannot move to Java 8, as the jdk15on coordinates receive no security fixes.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform