CVE-2026-59638: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bouncy Castle for Javato a version that resolves this vulnerability.Fixed in 1.85 - Upgrade
Upgrade
Bouncy Castle for Java LTSto a version that resolves this vulnerability.Fixed in 2.73.12 - Upgrade
Upgrade
Bouncy Castle for Java FIPS (BC-FJA) bctls-fips 1.0.X seriesto a version that resolves this vulnerability.Fixed in bctls-fips 1.0.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59638?
The severity of CVE-2026-59638 is rated at risk level 33.
How do I fix CVE-2026-59638?
To fix CVE-2026-59638, upgrade to Bouncy Castle for Java version 1.85 or later, or to the specified LTS or FIPS versions.
Which versions of Bouncy Castle are affected by CVE-2026-59638?
CVE-2026-59638 affects Bouncy Castle for Java before version 1.85, as well as specific LTS and FIPS versions prior to the mentioned updates.
What is the impact of CVE-2026-59638 on applications?
The impact of CVE-2026-59638 is that it enables the JSSE hostname verifier CN-fallback feature by default, which may lead to suboptimal security.
Is the CN-fallback feature configurable in Bouncy Castle regarding CVE-2026-59638?
Yes, the CN-fallback feature in Bouncy Castle is documented as an optional configuration, but it is enabled by default in the affected versions.