---
id: CVE-2026-5588
title: >-
  Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of
  the Bouncy Castle Inc
summary: >-
  Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of
  the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the
  Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the
  Bouncy Cast…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-327
  - CWE-347
vendor: Legion of the Bouncy Castle Inc.
product: bcpkix
affected:
  - bcpkix >= 1.67 < 1.80.2
  - bcpkix >= 1.81 < 1.81.1
  - bcpkix >= 1.82 < 1.84
  - bcpkix >= 2.0.6 < 2.0.11
  - bcpkix >= 2.1.7 < 2.1.11
  - bcpkix >= 2.73.7 < 2.73.11
patched:
  - jboss_eap_7_4_els_for_rhel_7_server
  - jboss_eap_8_1_for_rhel 8
  - jboss_eap_8_1_for_rhel 9
  - openshift_developer_tools_and_services 4.12
  - openshift_developer_tools_and_services 4.13
  - openshift_developer_tools_and_services 4.14
  - openshift_developer_tools_and_services 4.15
  - openshift_developer_tools_and_services 4.16
  - openshift_developer_tools_and_services 4.17
  - openshift_developer_tools_and_services 4.18
  - openshift_developer_tools_and_services 4.19
  - openshift_developer_tools_and_services 4.20
  - openshift_developer_tools_and_services 4.21
  - openshift_developer_tools_and_services 4.22
  - amq_broker 7.12.7
  - amq_broker 7.13.5
  - build_of_apache_camel_4_14_for_quarkus 3.27
  - jboss_enterprise_application_platform 7.4.25
  - jboss_enterprise_application_platform 8.1
  - openshift_dev_spaces 3.28
  - build_of_apache_camel_4_18_1_for_spring_boot 3.5.14
  - build_of_quarkus 3.20.6.SP1
  - build_of_quarkus 3.27.3.SP1
published: '2026-04-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:18:34.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5588'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://access.redhat.com/errata/RHSA-2026:11720'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11721'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13631'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14272'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14276'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17668'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18054'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18055'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18059'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21772'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53645'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53646'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60239'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60246'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60247'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60248'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60249'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60250'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60251'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60252'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60254'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60256'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60259'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-5588'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2458634'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5588.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:53806'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-5588'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5588'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00687
epssPercentile: 0.50628
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-15T19:35:32.235455Z'
scores:
  nvd: 7.5
  cna: 6.3
  vendor: 7.5
ingestedAt: '2026-07-16T12:53:55.945Z'
---

## Overview

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules).

 This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java.



This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:53644** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53644)
- **RHSA-2026:18054** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18054)
- **RHSA-2026:18055** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18055)
- **RHSA-2026:60247** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.12 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60247)
- **RHSA-2026:60249** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60249)
- **RHSA-2026:60248** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60248)
- **RHSA-2026:60239** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60239)
- **RHSA-2026:60251** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60251)
- **RHSA-2026:60246** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60246)
- **RHSA-2026:60250** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60250)
- **RHSA-2026:60252** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.19 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60252)
- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, Red Hat Enterprise Linux 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, … · no fix planned: Red Hat build of Debezium 3, Red Hat Enterprise Linux 8, Red Hat Fuse 7, Red Hat Process Automation 7, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5588.json)
- **RHSA-2026:53645** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 8 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53645)
- **RHSA-2026:53646** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53646)
