CVE-2026-59652: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
Published Aug 3, 2026
·Updated
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Affected Software
1 affected component
Bouncy Castle Java<1.85
Event History
Aug 3, 2026
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
DescriptionWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59652?
The severity of CVE-2026-59652 is rated at 45.
2
How do I fix CVE-2026-59652?
To fix CVE-2026-59652, update Bouncy Castle for Java to version 1.85 or later.
3
What is affected by CVE-2026-59652?
CVE-2026-59652 affects the legacy jdk1.4 LDAPStoreHelper in Bouncy Castle prior to version 1.85.
4
What kind of vulnerability is CVE-2026-59652?
CVE-2026-59652 is an LDAP filter injection vulnerability.
5
Who is impacted by CVE-2026-59652?
Any applications utilizing the legacy jdk1.4 LDAPStoreHelper in versions of Bouncy Castle earlier than 1.85 are impacted by CVE-2026-59652.