This issue affects BC-JAVA: from 1.74 before 1.84.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c3fc-8qff-9hwx | Bouncy Castle has an LDAP injection |
Wed, 29 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle
Bouncycastle bc-java |
|
| Vendors & Products |
Bouncycastle
Bouncycastle bc-java |
Wed, 15 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). LDAP Injection Vulnerability in LDAPStoreHelper.java This issue affects BC-JAVA: from 1.49 before 1.84. | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.84. |
| References |
| |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 15 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). LDAP Injection Vulnerability in LDAPStoreHelper.java This issue affects BC-JAVA: from 1.49 before 1.84. | |
| Title | LDAP Injection Vulnerability in LDAPStoreHelper.java | |
| Weaknesses | CWE-90 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-04-15T13:12:22.433Z
Reserved: 2026-01-06T03:18:21.572Z
Link: CVE-2026-0636
Updated: 2026-04-15T13:12:16.829Z
Status : Awaiting Analysis
Published: 2026-04-15T10:16:38.413
Modified: 2026-04-17T15:38:09.243
Link: CVE-2026-0636
OpenCVE Enrichment
Updated: 2026-04-15T14:53:11Z
Github GHSA