Vulnerability in Bouncy Castle for Java: BLS12_381 Basic Scheme Issues
CVE-2026-71891

7.1HIGH

What is CVE-2026-71891?

The vulnerability in Bouncy Castle for Java arises from inadequate validation during public key processing, enabling the acceptance of public keys built on non-canonical curves. Specifically, the keyValidate method in the BLS12_381 Basic Scheme fails to verify that a public key's associated elliptic curve strictly matches the expected G1 field parameters. This oversight could permit the recognition of phantom signers, potentially compromising the integrity of cryptographic operations. The flaw is particularly problematic when applications construct ECPoints directly from explicit, non-canonical curves. A fix has been introduced in version 1.86 to ensure rigorous checks on the curve's characteristics before proceeding with subgroup validations.

Affected Version(s)

BC-JAVA all 1.85 < 1.86

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bhargava Shastry
.