Vulnerability in Bouncy Castle Java Messaging Layer Security Implementation
CVE-2026-71885
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71885?
In the Bouncy Castle library for Java, prior to version 1.86, a vulnerability exists in its Messaging Layer Security (MLS) implementation. The issue arises from the failure to correctly bind an X.509 credential to a LeafNode's signature_key. This weakness allows an adversary to present another party's certificate while using a different signing key, thus impersonating that party's identity. In scenarios where external commits are permitted without thorough credential checks, an unauthorized actor could gain access as if they were the victim, leading to potential data exposure and message interception. The patched version mandates that the public key of the end-entity certificate matches the signature_key, thereby enhancing security in the signature validation process.
Affected Version(s)
BC-JAVA all 0 < 1.86
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
