LDAP injection in Bouncy Castle for Java - CVE-2026-0636

 

LDAP injection in Bouncy Castle for Java - CVE-2026-0636

Published: May 25, 2026


Vulnerability identifier: #VU132261
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0636
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate LDAP queries.

The vulnerability exists due to improper neutralization of special elements used in an LDAP query in LDAPStoreHelper when processing user-supplied input for LDAP queries. A remote attacker can supply crafted input to manipulate LDAP queries.

This issue is associated with the prov modules.


Affected software

Bouncy Castle for Java
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Anolis OS
Fusion Content-Aware Storage
IBM Tivoli Netcool Configuration Manager
ApplinX
Data Cataloging
MongoDB Enterprise Advanced with IBM
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Red Hat build of Quarkus
IBM Qradar SIEM
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
bouncycastle-javadoc
bouncycastle-jmail
bouncycastle-mail
bouncycastle-pg
bouncycastle-pkix
bouncycastle-tls
bouncycastle-util
bouncycastle
IBM Disconnected Log Collector

How to mitigate CVE-2026-0636

Install security update from vendor's website.

Bouncy Castle for Java - addressed in versions 1.80.2, 1.81.1, 1.84
Fusion Content-Aware Storage - update to 1.1.5
IBM Fusion HCI - update to 2.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle-javadoc - update to 1.84-1
bouncycastle-jmail - update to 1.84-1
bouncycastle-mail - update to 1.84-1
bouncycastle-pg - update to 1.84-1
bouncycastle-pkix - update to 1.84-1
bouncycastle-tls - update to 1.84-1
bouncycastle-util - update to 1.84-1
bouncycastle - update to 1.84-1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle - update to 1.84-150200.3.35.1
IBM Disconnected Log Collector - update to 2.0.1
Data Cataloging - update to 2.5.3
MongoDB Enterprise Advanced with IBM - update to 3.0.6
Red Hat build of Quarkus - addressed in versions 3.20.6.SP1, 3.27.3.SP1
Red Hat Camel for Spring Boot - update to 4.14

External References

Related Security Bulletins