{"id":"CVE-2026-59638","title":"In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in","summary":"In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc…","severity":"high","cwe":["CWE-297","CWE-295"],"published":"2026-08-03","updated":"2026-08-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59638","references":[{"url":"https://github.com/bcgit/bc-java/commit/5ac55351cd1a8a7184d41c96a7ee87df0770240a","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/commit/799bd15320a6310a447863638aa3df64acef829b","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE-2026-59638","label":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59638.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59638"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59638"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59638"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510201"}],"tags":["nvd","csaf","vex","red-hat"],"ingestedAt":"2026-08-03T01:21:07.697Z","epss":0.0021,"epssPercentile":0.1152,"vendor":"Red Hat","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cvssSource":"vendor","slug":"CVE-2026-59638","body":"## Overview\n\nIn Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59638.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202749,"id":"CVE-2026-59638","ts":1789403715516,"field":"cvss","old":null,"new":"7.4"},{"seq":202748,"id":"CVE-2026-59638","ts":1789403715516,"field":"severity","old":"none","new":"high"}]}