A critical flaw in Bouncy Castle Java certificate validation, tracked as CVE-2026-8763, allows attackers to bypass Name Constraints checks by appending a trailing dot to rfc822Name and URI values in certificates. The bug affects Bouncy Castle for Java before 1.85, BC-LTS before 2.73.12, and Bouncy Castle FIPS (BC-FJA) before 1.0.2.7, 2.0.2, and 2.1.3, and carries a CVSS 4.0 score of 9.3. The weakness is classified as CWE-295: Improper Certificate Validation and is considered remotely exploitable without privileges or user interaction.
Project maintainers said the issue stems from inconsistent handling of trailing dots in PKIXNameConstraintValidator: dNSName values were normalized for comparison, but rfc822Name and URI values were not, enabling excluded subtree checks to be evaded. An attacker controlling a name-constrained intermediate CA could issue certificates for email addresses or URI hosts that policy should have blocked. The vulnerable path is reachable through the Java 8+ PKIX certificate validation flow, and fixes were released in the patched versions above, including commit 2c28b253a446.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The bc-java project published a wiki advisory describing how trailing dots in rfc822Name and URI comparisons could bypass excluded subtree checks during certificate path validation. The advisory documented affected versions, exploitation conditions, and the fixing commit.
CVE-2026-8763 was published as a critical Bouncy Castle Java vulnerability involving improper certificate validation and a Name Constraints bypass. The issue affects BC before 1.85, BC-LTS before 2.73.12, and BC-FJA before 1.0.2.7, 2.0.2, and 2.1.3.
Bouncy Castle fixed a certificate path validation flaw in PKIXNameConstraintValidator that allowed Name Constraints bypass via trailing dots in rfc822Name and URI values. The fix was released in BC 1.85, BC-LTS 2.73.12, and BC-FJA 1.0.2.7, 2.0.2, and 2.1.3, with the change introduced in commit 2c28b253a446.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.