在 Bouncy Castle for Java 1.86 之前的版本中,针对 CMS 密钥传输接收方( )的可选密钥长度验证功能,在使用 RFC 9709 内容加密密钥派生( )的消息上从未执行。原本应选择在密钥派生 参数中携带的实际内容加密算法的代码分支,将加密密钥的字节数组与 对象标识符(OID)进行了比较。由于这是对字节数组与 之间的比较,其结果始终为 false,因此该检查最终回退到对外层包装 OID 的密钥长度查找。该 OID 标识的是密钥派生构造而非密码算法,且没有注册密钥长度,因此整个密钥长度比较被
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.78 ~ 1.86 | - |
|
| Legion of the Bouncy Castle Inc. | BC-FJA | 2.0.7 ~ 2.0.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71885 | 9.2 CRITICAL | MLS X.509 credential not bound to the LeafNode signature key |
| CVE-2026-71888 | 8.7 HIGH | CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent |
| CVE-2026-71889 | 8.7 HIGH | PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate |
| CVE-2026-71890 | 8.7 HIGH | MLS external commit can remove an arbitrary group member |
| CVE-2026-85515 | 8.2 HIGH | OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check |
| CVE-2026-71887 | 8.2 HIGH | OpenPGP data signature accepted from a signing subkey without cross-certification |
| CVE-2026-71883 | 8.2 HIGH | Native AES packet cipher returns the raw AES key on an alias |
| CVE-2026-71886 | 8.2 HIGH | OpenPGP certification accepted from a subkey without certification authority |
| CVE-2026-71891 | 7.1 HIGH | BLS12-381 key validation accepts a public key built on a foreign curve |
| CVE-2026-18040 | 5.9 MEDIUM | HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depen |
| CVE-2026-97873 | 5.3 MEDIUM | Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider |
No comments yet