Vulnerability in Bouncy Castle for Java: BLS12_381 Basic Scheme Issues
CVE-2026-71891
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71891?
The vulnerability in Bouncy Castle for Java arises from inadequate validation during public key processing, enabling the acceptance of public keys built on non-canonical curves. Specifically, the keyValidate method in the BLS12_381 Basic Scheme fails to verify that a public key's associated elliptic curve strictly matches the expected G1 field parameters. This oversight could permit the recognition of phantom signers, potentially compromising the integrity of cryptographic operations. The flaw is particularly problematic when applications construct ECPoints directly from explicit, non-canonical curves. A fix has been introduced in version 1.86 to ensure rigorous checks on the curve's characteristics before proceeding with subgroup validations.
Affected Version(s)
BC-JAVA all 1.85 < 1.86
