CVE-2026-5588

ADVISORY - github

Summary

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

EPSS Score: 0.00029 (0.082)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Use of a Broken or Risky Cryptographic Algorithm

ADVISORY - github

Use of a Broken or Risky Cryptographic Algorithm


NIST

CREATED

UPDATED

ADVISORY IDCVE-2026-5588
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.3medium

GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.3medium

Debian

CREATED

UPDATED

ADVISORY IDCVE-2026-5588
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY