Bug 2510190 (CVE-2026-59652)

Summary: CVE-2026-59652 bouncycastle: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Bouncy Castle for Java, specifically within the legacy `jdk1.4 LDAPStoreHelper`. This vulnerability allows for LDAP filter injection, where an attacker could provide specially crafted input. This could lead to unauthorized information disclosure or modification of data from the Lightweight Directory Access Protocol (LDAP) directory.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-03 02:01:22 UTC
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.