在 Bouncy Castle for Java 1.86 版本之前的实现中, 方法(以及 和所有 、 和 中依赖该方法进行验证和聚合验证的逻辑),接受了一个基于“外来”椭圆曲线(ECCurve)构建的公钥。该外来曲线仅与 BLS12-381 共享相同的域特征(field characteristic),但并非标准曲线。 由于质数阶子群检查(prime-order subgroup check)依赖于点自身所在曲线的协因子(cofactor)名称,而 在曲线的协因子为 1 时直接返回 true,因此,即使某个点实际
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.85< 1.86 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.85 ~ 1.86 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71885 | 9.2 CRITICAL | MLS X.509 credential not bound to the LeafNode signature key |
| CVE-2026-71888 | 8.7 HIGH | CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent |
| CVE-2026-71889 | 8.7 HIGH | PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate |
| CVE-2026-71890 | 8.7 HIGH | MLS external commit can remove an arbitrary group member |
| CVE-2026-85515 | 8.2 HIGH | OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check |
| CVE-2026-71887 | 8.2 HIGH | OpenPGP data signature accepted from a signing subkey without cross-certification |
| CVE-2026-71883 | 8.2 HIGH | Native AES packet cipher returns the raw AES key on an alias |
| CVE-2026-71886 | 8.2 HIGH | OpenPGP certification accepted from a subkey without certification authority |
| CVE-2026-71892 | 6.9 MEDIUM | CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys |
| CVE-2026-18040 | 5.9 MEDIUM | HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen |
| CVE-2026-97873 | 5.3 MEDIUM | Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider |
No comments yet