Description
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).
Severity (CVSS)
| Base score | 8.7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber |
| Provided by | CNA |
Weaknesses
- CWE-345 — CWE-345 Insufficient Verification of Data Authenticity
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 to <1.85 |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 to <2.73.12 |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 to <1.0.7; 2.0.0 to <2.0.7; 2.1.0 to <2.1.7 |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.4 to <1.0.7; 2.0.0 to <2.0.7; 2.1.0 to <2.1.7 |
References
Generated from the official CVE List on 03 Aug 2026 08:53 UTC.