Intel

AIKIDO-2026-67368

bcprov-jdk14 is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2026-71889 Published Sep 30, 2026

85

High Risk

This Affects:

JAVAbcprov-jdk14
1.43 - 1.85.2
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

The legacy org.bouncycastle.x509.PKIXCertPathReviewer skips X.509 name-constraint checks for the target certificate and can report a prohibited leaf certificate as valid. The fix applies name constraints at path index zero while preserving target-specific RFC behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use org.bouncycastle.x509.PKIXCertPathReviewer as the trust decision for certificate paths constrained by permitted or excluded names.

Background info

bcprov-jdk14 is vulnerable to Improper Certificate Validation in versions 1.43 - 1.85.2.

How to fix this

Upgrade the bcprov-jdk14 library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform