CVE-2026-8763High· 7.4▾ TwilightIn Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.4%
7.4 → —
high → none
— → 7.4
none → high
7.4 → —
high → none
— → 7.4
none → high
7.4 → —
high → none
— → 7.4
none → high
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.bouncycastle:bc-fips < 1.0.2.7org.bouncycastle:bc-fips >= 2.0.0, < 2.0.2org.bouncycastle:bc-fips >= 2.1.0, < 2.1.3org.bouncycastle:bcprov-jdk18on < 1.85org.bouncycastle:bcprov-lts8on < 2.73.12org.bouncycastle:bcprov-jdk15to18 < 1.85Patched in:
org.bouncycastle:bc-fips 1.0.2.7org.bouncycastle:bc-fips 2.0.2org.bouncycastle:bc-fips 2.1.3org.bouncycastle:bcprov-jdk18on 1.85org.bouncycastle:bcprov-lts8on 2.73.12org.bouncycastle:bcprov-jdk15to18 1.85Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62243High· 7.5Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is use…
CVE-2026-56820High· 7.4io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820)
CVE-2026-15554High· 7.4the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication
CVE-2026-87795High· 8.2com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)
CVE-2026-89046High· 8.2zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)
CVE-2026-45819High· 7.5baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.