← Vulnerability feed

Vulnerability record · CVE-2026-12860 · published 3 August 2026

CVE-2026-12860: Bouncycastle bc-java improper verification of cryptographic signature vulnerability

Bouncycastle · Bc Java

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

8.7 CVSS 4.0 High EPSS 0.17% · top 94.2% CWE-347 · Improper verification of cryptographic signature
8.7CVSS 4.0 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
28 Aug 2026Last modified by NVD

Description

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-12860 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6721Bouncycastle bc-java vulnerabilityThe Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and rem…EPSS 2.4%9.8CVE-2018-1000613Bouncycastle bc-java vulnerabilityLegion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externall…EPSS 4.8%9.3CVE-2026-58062Bouncycastle bc-java improper certificate validation vulnerabilityIn Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Cast…EPSS 0.27%9.3CVE-2026-59650Bouncycastle bc-java improper input validation vulnerabilityIn Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS b…EPSS 0.45%9.3CVE-2026-8763Bouncycastle bc-java improper certificate validation vulnerabilityIn Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java…EPSS 0.45%9.3CVE-2026-59638Bouncycastle bc-java vulnerabilityIn Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bounc…EPSS 0.35%8.7CVE-2026-14682Bouncycastle bc-java vulnerabilityIn Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Cast…EPSS 0.33%8.7CVE-2026-12803Bouncycastle bc-java vulnerabilityIn Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects…EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2026-12860), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.