OpenPGP API Vulnerability in Bouncy Castle for Java Affects Digital Signatures
CVE-2026-71887
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71887?
The OpenPGP API in Bouncy Castle for Java prior to version 1.86 contains a flaw where a signing subkey with a Subkey Binding signature lacking an embedded Primary Key Binding signature can erroneously be accepted. This occurs under circumstances where the binding signature omits the Key Flags subpacket. Consequently, an attacker could leverage a victim's public signing subkey to craft a malicious certificate, leading to the misattribution of valid signatures to an attacker-controlled identity. Unlike GnuPG, which rejects such certificates, the flaw may allow the verification of signatures against an attacker's certificate, severely undermining the integrity of the digital signature verification process. It's crucial for users to update to the latest version to mitigate this vulnerability.
Affected Version(s)
BC-JAVA all 1.81 < 1.86
