Vulnerability in Bouncy Castle Java Library Affects OpenPGP Certificate API
CVE-2026-71886

8.2HIGH

What is CVE-2026-71886?

The Bouncy Castle for Java library contains a vulnerability in the OpenPGP certificate API that permits third-party certifications without the necessary authority checks. This occurs when the API validates signatures based solely on issuer key identifiers, disregarding the certification capabilities of the keys involved. Specifically, a subkey that lacks the authority to certify can still issue user ID certifications, leading to potential trust misattribution in applications relying on these API functions. By promoting compromised subkeys to the primary key's identity-issuing authority, the library can inadvertently endorse malicious assertions. The vulnerability underscores the importance of rigorous validation of key capabilities during the certification process.

Affected Version(s)

BC-JAVA all 1.81 < 1.86

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bhargava Shastry
.