在 Bouncy Castle for Java 1.86 之前的版本中,高级 OpenPGP 证书 API 接受了来自发行证书的任何组件密钥(component key)的第三方认证或信任委派,而未要求该组件密钥必须拥有认证权限。 和 方法通过将被验证签名的发行方密钥标识符与第三方证书中的所有密钥进行匹配,从而解析出第三方签名;随后验证该发行组件的绑定链及其签名本身。然而,在签名创建时,系统并未检查该发行组件密钥是否设置了 RFC 9580 第 5.2.3.29 节中定义的“认证密钥标志位”(CERTIFY_OT
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.81< 1.86 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.81 ~ 1.86 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71885 | 9.2 CRITICAL | MLS X.509 credential not bound to the LeafNode signature key |
| CVE-2026-71888 | 8.7 HIGH | CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent |
| CVE-2026-71889 | 8.7 HIGH | PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate |
| CVE-2026-71890 | 8.7 HIGH | MLS external commit can remove an arbitrary group member |
| CVE-2026-85515 | 8.2 HIGH | OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check |
| CVE-2026-71887 | 8.2 HIGH | OpenPGP data signature accepted from a signing subkey without cross-certification |
| CVE-2026-71883 | 8.2 HIGH | Native AES packet cipher returns the raw AES key on an alias |
| CVE-2026-71891 | 7.1 HIGH | BLS12-381 key validation accepts a public key built on a foreign curve |
| CVE-2026-71892 | 6.9 MEDIUM | CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys |
| CVE-2026-18040 | 5.9 MEDIUM | HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen |
| CVE-2026-97873 | 5.3 MEDIUM | Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider |
No comments yet