PT-2026-104567 · Unknown · Bouncy Castle For Java
CVE-2026-71885
·
Published
2026-10-03
·
Updated
2026-10-04
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/U:Amber |
Name of the Vulnerable Software and Affected Versions
Bouncy Castle for Java versions prior to 1.86
Description
The Messaging Layer Security (MLS, RFC 9420) implementation fails to bind an X.509 credential to a
LeafNode signature key. The LeafNode.verify() function validates a leaf signature against the signature key contained within the leaf, but it does not parse or validate the stored X.509 certificate chain. Consequently, the end-entity certificate's public key is not required to match the signature key. This allows an unauthenticated attacker to impersonate a victim by presenting the victim's certificate while signing the leaf and the enclosing KeyPackage with an unrelated key. If the deployment allows external commits without independent credential checks, the attacker could be admitted under the victim's identity, evict the victim, derive the current epoch, decrypt group messages, and send messages as the victim. This issue occurs within the TreeKEM.LeafNode component and the KeyPackage.verify() process.Recommendations
Update to version 1.86 or later.
Exploit
Fix
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bouncy Castle For Java