---
id: CVE-2026-59652
title: >-
  In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4
  LDAPStoreHelper.
summary: >-
  In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4
  LDAPStoreHelper.
severity: none
cwe:
  - CWE-90
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59652'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/27c468af54ee6c6af87eab5a3a8468dce17e24a0
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-59652'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
ingestedAt: '2026-08-03T01:21:08.101Z'
epss: 0.00297
epssPercentile: 0.22506
---

## Overview

In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
