Vulnerability GHSA-c3fc-8qff-9hwx

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
April 17, 2026 at 06:31 PM UTC
Bouncy Castle has an LDAP injection
1.74.0 - 1.83.0
1.74.0 - 1.83.0

Summary

Bouncy Castle has an LDAP injection

Details

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.

This issue affects BC-JAVA: from 1.74 before 1.84.

Timeline

Published
5 months ago
April 17, 2026 at 06:31 PM UTC
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Fixed (1.84)
Unknown
Unknown
Last Modified
18 days ago
September 10, 2026 at 03:51 AM UTC