CVE-2026-58059: Quadratic-time escaping when stringifying X.500 distinguished names
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58059?
CVE-2026-58059 has a severity rating of high with a CVSS score of 8.7.
How do I fix CVE-2026-58059?
To fix CVE-2026-58059, upgrade to Bouncy Castle for Java version 1.85 or later, or the respective LTS or FIPS versions mentioned in the advisory.
What software is affected by CVE-2026-58059?
CVE-2026-58059 affects Bouncy Castle for Java, Bouncy Castle for Java LTS, and Bouncy Castle for Java FIPS.
What is the nature of the vulnerability in CVE-2026-58059?
CVE-2026-58059 involves a quadratic-time escaping issue when stringifying X.500 distinguished names.
When was CVE-2026-58059 published?
CVE-2026-58059 was published on August 3, 2026.