CVE-2026-8763 is an X.509 Name Constraints validation bypass in Bouncy Castle for Java. PKIXNameConstraintValidator strips trailing dots before dNSName comparisons but does not apply equivalent normalization in the rfc822Name isEmailConstrained and URI isURIConstrained paths, which compare extracted hosts using equalsIgnoreCase. A trailing dot can therefore prevent a certificate identity from matching an excluded subtree, allowing certificate path validation to succeed despite the exclusion policy. The vulnerable logic is reachable through PKIXCertPathValidatorSpi_8 and RFC3280CertPathUtilities.processCertBC on Java 8 and later. Affected releases are Bouncy Castle Java before 1.85, Java LTS before 2.73.12, and BC-FJA before 1.0.2.7 in the 1.0.X branch, 2.0.2 in the 2.0.X branch, and 2.1.3 in the 2.1.X branch.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible, low-complexity vulnerability in Atlassian Jira Service Desk that requires no privileges or user interaction and can result in high confidentiality and integrity impact, with no availability impact indicated.
A Bouncy Castle for Java Name Constraints validation bypass caused by trailing dots in rfc822Name and URI values. It affects Bouncy Castle for Java releases before 1.85, Java LTS releases before 2.73.12, and specified BC-FJA/FIPS releases.
A critical certificate validation flaw in Bouncy Castle Java libraries that allows Name Constraints bypass via a trailing dot in rfc822Name and URI values, potentially undermining PKIX certificate validation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.