CVE-2026-58062
CRITICALStapled OCSP response accepted without binding to the checked certificate
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-58062. PoCs published by xiaoqiMikko.
AI-analyzed exploit summary This repository provides a Java-based scanner tool to detect vulnerable versions of Bouncy Castle libraries (CVE-2026-58062 and related CVEs) in JAR/WAR files or Maven coordinates. It performs static analysis of artifact metadata, manifests, and filenames to assess exposure to disclosed vulnerabilities without exploiting them.
Description
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Exploits (1)
This repository provides a Java-based scanner tool to detect vulnerable versions of Bouncy Castle libraries (CVE-2026-58062 and related CVEs) in JAR/WAR files or Maven coordinates. It performs static analysis of artifact metadata, manifests, and filenames to assess exposure to disclosed vulnerabilities without exploiting them.
References (3)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber