Vulnerability in Bouncy Castle Java Library Affects OpenPGP Certificate API
CVE-2026-71886
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71886?
The Bouncy Castle for Java library contains a vulnerability in the OpenPGP certificate API that permits third-party certifications without the necessary authority checks. This occurs when the API validates signatures based solely on issuer key identifiers, disregarding the certification capabilities of the keys involved. Specifically, a subkey that lacks the authority to certify can still issue user ID certifications, leading to potential trust misattribution in applications relying on these API functions. By promoting compromised subkeys to the primary key's identity-issuing authority, the library can inadvertently endorse malicious assertions. The vulnerability underscores the importance of rigorous validation of key capabilities during the certification process.
Affected Version(s)
BC-JAVA all 1.81 < 1.86
