NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-5588
Summary

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

Publication Date April 15, 2026, 7:16 p.m.
Registration Date April 17, 2026, 4:11 a.m.
Last Update April 16, 2026, 2:17 a.m.
Related information, measures and tools
Common Vulnerabilities List