Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-17507— MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range sender

Quick assessment

Affected
Legion of the Bouncy Castle Inc. BC-JAVA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Bouncy Castle for Java 1.86 版本之前,其 MLS 实现( )将 RFC 9420 中定义的无符号 32 位整数 存储在一个有符号的 类型变量中。因此,当网络传输值(wire value)的最高有效位(即符号位)被置位时,该值会被解码为负数。 这种编码是合法的,而非格式错误的输入,因此必须能够正确解码。这是因为 MLS 互操作性测试向量会遍历该字段的全部取值范围,确保往返一致性。 在 和 方法中,解码后的值会与树的叶子节点数量直接进行比较。由于使用的是有符号整数比较,任何负数值都会被判

CVSS 8.7 · High EPSS 0.32% · P23

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
Legion of the Bouncy Castle Inc. BC-JAVA 1.73< 1.86 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17507

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range sender
Source: CVE Program / CVE List V5
Vulnerability Description
In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate encoding rather than malformed input, and it must still decode, since the MLS interop test vectors round-trip the full range. GroupKeySet.SecretTree.hasLeaf and Group.validateRemove compared the decoded value directly against the tree's leaf count, and a signed comparison treats any negative int as less than a positive bound, so an out-of-range sender passed the membership check. In the hasLeaf case the SenderData of an unprotected PrivateMessage could then drive LeafIndex.directPath through NodeIndex.parent() arithmetic that never reaches the tree root, growing the resulting node list without bound until the JVM exhausted its heap. A single small message from any current group member could therefore deny service to every other member of the group. Both comparisons now interpret the value as unsigned via Integer.toUnsignedLong, rejecting an out-of-range sender however it was encoded; well-formed leaf indices are unaffected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
有符号至无符号转换错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Legion of the Bouncy Castle Inc. BC-JAVA 1.73 ~ 1.86 -

II. Public POCs for CVE-2026-17507

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17507

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-17507 (1)

News Coverage for CVE-2026-17507 (1)

Same Patch Batch · Legion of the Bouncy Castle Inc. · 2026-10-02 · 24 CVEs total

CVE-2026-63569 9.1 CRITICAL MTI/A0 DHAgreement does not validate the peer's ephemeral value
CVE-2026-63571 8.7 HIGH Attribute certificate path validation does not verify the attribute certificate's signatur
CVE-2026-63566 8.7 HIGH DTLS handshake reassembler allocates buffer from unchecked 24-bit length
CVE-2026-63574 8.7 HIGH Unbounded allocation from OpenPGP signature and user attribute subpacket lengths
CVE-2026-63568 8.7 HIGH Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion
CVE-2026-103600 8.7 HIGH Unbounded ASN.1 nesting depth causes process-terminating stack overflow
CVE-2026-103604 8.7 HIGH Quadratic-time escaping when converting X.509 distinguished names to strings
CVE-2026-103603 8.7 HIGH Unbounded HSS public key level count allows huge array allocation during signature verific
CVE-2026-16000 8.7 HIGH KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used
CVE-2026-103602 8.2 HIGH Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts
CVE-2026-18036 8.2 HIGH NTRU leaks private key information by reducing secret values with a non-constant-time inte
CVE-2026-63577 8.2 HIGH Name Constraints bypass: directoryName constraint matched at any position in the DN instea
CVE-2026-63576 8.2 HIGH URI name constraints checked against a mis-parsed host
CVE-2026-63573 8.2 HIGH Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap
CVE-2026-103601 8.2 HIGH CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a
CVE-2026-63567 8.2 HIGH IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
CVE-2026-15999 8.2 HIGH AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication
CVE-2026-16001 8.2 HIGH IesEngine stream-mode MAC forgery via length-dependent KDF split
CVE-2026-63578 7.1 HIGH Unbounded PBE iteration count when decrypting PKCS#8 private keys
CVE-2026-63570 7.1 HIGH Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-17507

No comments yet


Leave a comment