---
id: CVE-2026-8763
title: >-
  In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing
  dot in rfc822Name and URI
summary: >-
  In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing
  dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS
  before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips
  1.0.2.7 (1.…
severity: high
cwe:
  - CWE-295
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8763'
references:
  - url: >-
      https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE-2026-8763'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8763.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-8763'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510198'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-8763'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8763'
  - url: 'https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763'
  - url: 'https://github.com/bcgit/bc-java/releases/tag/r1rv85v2'
  - url: 'https://github.com/advisories/GHSA-9pwp-9qqc-pr26'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
ingestedAt: '2026-08-03T01:21:08.158Z'
epss: 0.0043
epssPercentile: 0.36703
vendor: Red Hat
product: Red Hat Ceph Storage 9
affected:
  - ceph_storage 9
  - jboss_enterprise_application_platform 7
  - single_sign_on 7
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
aliases:
  - GHSA-9pwp-9qqc-pr26
ecosystem: maven
patched:
  - 'org.bouncycastle:bc-fips 1.0.2.7'
  - 'org.bouncycastle:bc-fips 2.0.2'
  - 'org.bouncycastle:bc-fips 2.1.3'
  - 'org.bouncycastle:bcprov-jdk18on 1.85'
  - 'org.bouncycastle:bcprov-lts8on 2.73.12'
  - 'org.bouncycastle:bcprov-jdk15to18 1.85'
scores:
  vendor: 7.4
  ghsa: 9.1
---

## Overview

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Ceph Storage 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat Ceph Storage 9, Red Hat Single Sign-On 7 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8763.json)

## Package advisory (CVE-2026-8763)

Affected packages:

- `org.bouncycastle:bc-fips < 1.0.2.7`
- `org.bouncycastle:bc-fips >= 2.0.0, < 2.0.2`
- `org.bouncycastle:bc-fips >= 2.1.0, < 2.1.3`
- `org.bouncycastle:bcprov-jdk18on < 1.85`
- `org.bouncycastle:bcprov-lts8on < 2.73.12`
- `org.bouncycastle:bcprov-jdk15to18 < 1.85`

Patched in:

- `org.bouncycastle:bc-fips 1.0.2.7`
- `org.bouncycastle:bc-fips 2.0.2`
- `org.bouncycastle:bc-fips 2.1.3`
- `org.bouncycastle:bcprov-jdk18on 1.85`
- `org.bouncycastle:bcprov-lts8on 2.73.12`
- `org.bouncycastle:bcprov-jdk15to18 1.85`

Source: https://github.com/advisories/GHSA-9pwp-9qqc-pr26
