Vulnerability in Bouncy Castle for Java Affects AuthenticatedData Parsing
CVE-2026-71888
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71888?
In Bouncy Castle for Java before version 1.86, a flaw in the streaming CMS AuthenticatedData parser allows for a message to contain mismatched digestAlgorithm and authAttrs. This flaw can be exploited by an attacker who alters a message in transit, potentially introducing unauthorized authenticated attributes, which may lead to erroneous authorization or routing decisions based on these maliciously modified values. This vulnerability compromises the integrity of message authentication, allowing attackers to manipulate attributes without needing access to the encryption keys. Subsequent versions provide fixes to ensure that mismatches are rejected and improve security against such exploitation.
Affected Version(s)
BC-FJA all 1.0.0 < 1.0.13
BC-FJA all 2.0.0 < 2.0.13
BC-FJA all 2.1.0 < 2.1.13
