在 Bouncy Castle for Java 1.86 之前的版本中,流式 CMS AuthenticatedData(认证数据)解析器接受了一条消息,其 (摘要算法)和 (认证属性)字段在是否包含认证属性上存在不一致。根据 RFC 5652 第 9.1 节,这两个字段应当配对使用:只要存在 ,就必须存在 ;而第 9.2 节规定,当存在 时,MAC(消息认证码)应覆盖 的 DER 编码;当不存在 时,MAC 则直接覆盖 (内容)OCTET STRING。 由于 必须在构造函数中决定采用哪种 MAC 验证方式,而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0< 1.0.13 |
affected |
2.0.0< 2.0.13 |
affected | ||
2.1.0< 2.1.13 |
affected | ||
2.0.0< 2.0.8 |
affected | ||
2.1.0< 2.1.8 |
affected | ||
| Legion of the Bouncy Castle Inc. | BC-JAVA | < 1.86 |
affected |
1.70< 1.86 |
affected | ||
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0< 2.73.13 |
affected |
2.73.0< 2.73.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 ~ 1.86 | - |
|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.70 ~ 1.86 | - |
|
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 ~ 2.73.13 | - |
|
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 ~ 2.73.13 | - |
|
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 ~ 1.0.13 | - |
|
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.0.0 ~ 2.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71885 | 9.2 CRITICAL | MLS X.509 credential not bound to the LeafNode signature key |
| CVE-2026-71889 | 8.7 HIGH | PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate |
| CVE-2026-71890 | 8.7 HIGH | MLS external commit can remove an arbitrary group member |
| CVE-2026-85515 | 8.2 HIGH | OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check |
| CVE-2026-71887 | 8.2 HIGH | OpenPGP data signature accepted from a signing subkey without cross-certification |
| CVE-2026-71883 | 8.2 HIGH | Native AES packet cipher returns the raw AES key on an alias |
| CVE-2026-71886 | 8.2 HIGH | OpenPGP certification accepted from a subkey without certification authority |
| CVE-2026-71891 | 7.1 HIGH | BLS12-381 key validation accepts a public key built on a foreign curve |
| CVE-2026-71892 | 6.9 MEDIUM | CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys |
| CVE-2026-18040 | 5.9 MEDIUM | HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen |
| CVE-2026-97873 | 5.3 MEDIUM | Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider |
No comments yet