Use of a broken or risky cryptographic algorithm in Bouncy Castle for Java - CVE-2026-5588
Published: May 25, 2026
Vulnerability identifier: #VU132260
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-5588
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass signature verification.
The vulnerability exists due to use of a broken or risky cryptographic algorithm in the PKIX draft CompositeVerifier when processing composite signatures. A remote attacker can provide an empty signature sequence to bypass signature verification.
Affected software
Bouncy Castle for Java
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Anolis OS
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
Red Hat build of Quarkus
IBM Tivoli Netcool Configuration Manager
ApplinX
MongoDB Enterprise Advanced with IBM
IBM Sterling Connect:Direct for Microsoft Windows
IBM DB2
IBM InfoSphere Information Server
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
bouncycastle-javadoc
bouncycastle-jmail
bouncycastle-mail
bouncycastle-pg
bouncycastle-pkix
bouncycastle-tls
bouncycastle-util
bouncycastle
IBM Disconnected Log Collector
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Anolis OS
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
Red Hat build of Quarkus
IBM Tivoli Netcool Configuration Manager
ApplinX
MongoDB Enterprise Advanced with IBM
IBM Sterling Connect:Direct for Microsoft Windows
IBM DB2
IBM InfoSphere Information Server
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
bouncycastle-javadoc
bouncycastle-jmail
bouncycastle-mail
bouncycastle-pg
bouncycastle-pkix
bouncycastle-tls
bouncycastle-util
bouncycastle
IBM Disconnected Log Collector
How to mitigate CVE-2026-5588
Install security update from vendor's website.
Bouncy Castle for Java - addressed in versions 1.80.2, 1.81.1, 1.84
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle-javadoc - update to 1.84-1
bouncycastle-jmail - update to 1.84-1
bouncycastle-mail - update to 1.84-1
bouncycastle-pg - update to 1.84-1
bouncycastle-pkix - update to 1.84-1
bouncycastle-tls - update to 1.84-1
bouncycastle-util - update to 1.84-1
bouncycastle - update to 1.84-1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle - update to 1.84-150200.3.35.1
IBM Disconnected Log Collector - update to 2.0.1
MongoDB Enterprise Advanced with IBM - update to 3.0.6
Red Hat build of Quarkus - addressed in versions 3.20.6.SP1, 3.27.3.SP1
Red Hat Camel for Spring Boot - update to 4.14
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.57, 6.4.0.4.28
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle-javadoc - update to 1.84-1
bouncycastle-jmail - update to 1.84-1
bouncycastle-mail - update to 1.84-1
bouncycastle-pg - update to 1.84-1
bouncycastle-pkix - update to 1.84-1
bouncycastle-tls - update to 1.84-1
bouncycastle-util - update to 1.84-1
bouncycastle - update to 1.84-1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle - update to 1.84-150200.3.35.1
IBM Disconnected Log Collector - update to 2.0.1
MongoDB Enterprise Advanced with IBM - update to 3.0.6
Red Hat build of Quarkus - addressed in versions 3.20.6.SP1, 3.27.3.SP1
Red Hat Camel for Spring Boot - update to 4.14
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.57, 6.4.0.4.28
External References
Related Security Bulletins
- Multiple vulnerabilities in Bouncy Castle for Java
- Anolis OS update for bouncycastle
- Multiple vulnerabilities in Red Hat build of Quarkus 3.20.6
- Multiple vulnerabilities in Red Hat build of Quarkus 3.27.3
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- SUSE update for bouncycastle
- IBM Sterling Connect:Direct for Microsoft Windows update for Bouncy Castle
- IBM Sterling Connect:Direct Web Services update for BC-JAVA bcpkix
- MongoDB Enterprise Advanced with IBM update for Legion of the Bouncy Castle
- Multiple vulnerabilities in IBM ApplinX
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- Multiple vulnerabilities in IBM Db2
- IBM InfoSphere Information Server update for Legion of the Bouncy Castle Inc.
- Multiple vulnerabilities in IBM Disconnected Log Collector
- IBM Watson Speech Services Cartridge update for Legion of the Bouncy Castle
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Sterling Secure Proxy