OpenPGP API Vulnerability in Bouncy Castle for Java Affects Digital Signatures
CVE-2026-71887

8.2HIGH

What is CVE-2026-71887?

The OpenPGP API in Bouncy Castle for Java prior to version 1.86 contains a flaw where a signing subkey with a Subkey Binding signature lacking an embedded Primary Key Binding signature can erroneously be accepted. This occurs under circumstances where the binding signature omits the Key Flags subpacket. Consequently, an attacker could leverage a victim's public signing subkey to craft a malicious certificate, leading to the misattribution of valid signatures to an attacker-controlled identity. Unlike GnuPG, which rejects such certificates, the flaw may allow the verification of signatures against an attacker's certificate, severely undermining the integrity of the digital signature verification process. It's crucial for users to update to the latest version to mitigate this vulnerability.

Affected Version(s)

BC-JAVA all 1.81 < 1.86

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arpan Sharma
.