CVE-2026-5588

EUVD-2026-22871
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).


PKIX draft CompositeVerifier accepts empty signature sequence as valid.


This issue affects BC-JAVA: from 1.49 before 1.84.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---