LDAP injection in The Bouncy Castle Crypto Package For Java - CVE-2026-0636
Published: May 25, 2026
The Bouncy Castle Crypto Package For Java
Detailed vulnerability description
The vulnerability allows a remote attacker to manipulate LDAP queries.
The vulnerability exists due to improper neutralization of special elements used in an LDAP query in LDAPStoreHelper when processing user-supplied input for LDAP queries. A remote attacker can supply crafted input to manipulate LDAP queries.
This issue is associated with the prov modules.