Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-71885— MLS X.509 credential not bound to the LeafNode signature key

Quick assessment

Affected
Legion of the Bouncy Castle Inc. BC-JAVA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Java 版 Bouncy Castle 1.86 之前的版本中,消息层安全(MLS,RFC 9420)的实现未将 X.509 证书凭据与 LeafNode 的 signature_key(签名密钥)进行绑定。LeafNode.verify() 方法仅检查叶节点自身的签名是否与其携带的 signature_key 匹配;而证书链中的 X.509 证书虽然被存储,但从未被解析或验证。因此,最终实体证书的公钥无需与 signature_key 匹配,这不符合 RFC 9420 第 5.3 节的要求。 攻击者因此可以

CVSS 9.2 · Critical EPSS 0.19% · P8

Affected Version Matrix 1

VendorProduct Version RangeStatus
Legion of the Bouncy Castle Inc. BC-JAVA < 1.86 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71885

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MLS X.509 credential not bound to the LeafNode signature key
Source: CVE Program / CVE List V5
Vulnerability Description
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Legion of the Bouncy Castle Inc. BC-JAVA 0 ~ 1.86 -

II. Public POCs for CVE-2026-71885

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71885

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-71885 (1)

Security Blog Posts for CVE-2026-71885 (1)

Same Patch Batch · Legion of the Bouncy Castle Inc. · 2026-10-03 · 12 CVEs total

CVE-2026-71888 8.7 HIGH CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent
CVE-2026-71889 8.7 HIGH PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate
CVE-2026-71890 8.7 HIGH MLS external commit can remove an arbitrary group member
CVE-2026-85515 8.2 HIGH OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check
CVE-2026-71887 8.2 HIGH OpenPGP data signature accepted from a signing subkey without cross-certification
CVE-2026-71883 8.2 HIGH Native AES packet cipher returns the raw AES key on an alias
CVE-2026-71886 8.2 HIGH OpenPGP certification accepted from a subkey without certification authority
CVE-2026-71891 7.1 HIGH BLS12-381 key validation accepts a public key built on a foreign curve
CVE-2026-71892 6.9 MEDIUM CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys
CVE-2026-18040 5.9 MEDIUM HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen
CVE-2026-97873 5.3 MEDIUM Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider

IV. Related Vulnerabilities

V. Comments for CVE-2026-71885

No comments yet


Leave a comment