Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-71888— CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent

Quick assessment

Affected
Legion of the Bouncy Castle Inc. BC-JAVA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Bouncy Castle for Java 1.86 之前的版本中,流式 CMS AuthenticatedData(认证数据)解析器接受了一条消息,其 (摘要算法)和 (认证属性)字段在是否包含认证属性上存在不一致。根据 RFC 5652 第 9.1 节,这两个字段应当配对使用:只要存在 ,就必须存在 ;而第 9.2 节规定,当存在 时,MAC(消息认证码)应覆盖 的 DER 编码;当不存在 时,MAC 则直接覆盖 (内容)OCTET STRING。 由于 必须在构造函数中决定采用哪种 MAC 验证方式,而

CVSS 8.7 · High EPSS 0.11% · P1

Possible ATT&CK Techniques 1 AI

T1562

Affected Version Matrix 9

VendorProduct Version RangeStatus
Legion of the Bouncy Castle Inc. BC-FJA 1.0.0< 1.0.13 affected
2.0.0< 2.0.13 affected
2.1.0< 2.1.13 affected
2.0.0< 2.0.8 affected
2.1.0< 2.1.8 affected
Legion of the Bouncy Castle Inc. BC-JAVA < 1.86 affected
1.70< 1.86 affected
Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.0< 2.73.13 affected
2.73.0< 2.73.13 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71888

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent
Source: CVE Program / CVE List V5
Vulnerability Description
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2 makes the MAC cover the DER encoding of authAttrs when they are present and the eContent OCTET STRING directly when they are not. CMSAuthenticatedDataParser has to choose between those two in its constructor, before it can reach authAttrs, which comes later in the SEQUENCE, so it chose on digestAlgorithm alone: for a message with digestAlgorithm absent but authAttrs present it verified the content MAC and then returned the attributes through getAuthAttrs() as though they had been authenticated, when the MAC had never covered them. An attacker able to modify a message in transit could insert an authenticated attribute, such as an RFC 2634 ESSSecurityLabel, into an otherwise valid message while holding neither the key-encryption key nor the content-MAC key, and an application taking an authorization, routing or labelling decision from those attributes would act on attacker-chosen values. The content itself remained MAC-bound. asn1.cms.AuthenticatedData now rejects the mismatched pairing when parsing and CMSAuthenticatedDataParser cross-checks the two fields once authAttrs is read. This is a variant of CVE-2026-59642, which bound the content to the MAC for messages that legitimately carry authAttrs, and which does not address this case. This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), and bcutil-fips 2.0.8 (2.0.X series) and 2.1.8 (2.1.X series).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
完整性检查值验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Legion of the Bouncy Castle Inc. BC-JAVA 0 ~ 1.86 -
Legion of the Bouncy Castle Inc. BC-JAVA 1.70 ~ 1.86 -
Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.0 ~ 2.73.13 -
Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.0 ~ 2.73.13 -
Legion of the Bouncy Castle Inc. BC-FJA 1.0.0 ~ 1.0.13 -
Legion of the Bouncy Castle Inc. BC-FJA 2.0.0 ~ 2.0.8 -

II. Public POCs for CVE-2026-71888

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71888

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-71888 (1)

News Coverage for CVE-2026-71888 (1)

Same Patch Batch · Legion of the Bouncy Castle Inc. · 2026-10-03 · 12 CVEs total

CVE-2026-71885 9.2 CRITICAL MLS X.509 credential not bound to the LeafNode signature key
CVE-2026-71889 8.7 HIGH PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate
CVE-2026-71890 8.7 HIGH MLS external commit can remove an arbitrary group member
CVE-2026-85515 8.2 HIGH OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check
CVE-2026-71887 8.2 HIGH OpenPGP data signature accepted from a signing subkey without cross-certification
CVE-2026-71883 8.2 HIGH Native AES packet cipher returns the raw AES key on an alias
CVE-2026-71886 8.2 HIGH OpenPGP certification accepted from a subkey without certification authority
CVE-2026-71891 7.1 HIGH BLS12-381 key validation accepts a public key built on a foreign curve
CVE-2026-71892 6.9 MEDIUM CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys
CVE-2026-18040 5.9 MEDIUM HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen
CVE-2026-97873 5.3 MEDIUM Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider

IV. Related Vulnerabilities

V. Comments for CVE-2026-71888

No comments yet


Leave a comment