Intel

AIKIDO-2026-695180

bcpkix-jdk18on is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2026-71889 Published Yesterday

85

High Risk

This Affects:

JAVAbcpkix-jdk18on
1.74 - 1.85
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer skips X.509 name-constraint checks for the target certificate and can report a prohibited leaf certificate as valid. The fix applies name constraints at path index zero while preserving target-specific RFC behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer as the trust decision for certificate paths constrained by permitted or excluded names.

Background info

bcpkix-jdk18on is vulnerable to Improper Certificate Validation in versions 1.74 - 1.85.

How to fix this

Upgrade the bcpkix-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform