PT-2026-104569 · Unknown · Bouncy Castle For Java
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber |
Name of the Vulnerable Software and Affected Versions
Bouncy Castle for Java versions prior to 1.86
Description
Validation of an MLS (RFC 9420) external commit's proposal list in the
validateExternalCachedProposals() function of org.bouncycastle.mls.protocol.Group failed to verify that a removed leaf was associated with the joiner. While RFC 9420 allows a joiner to remove an old version of themselves via a Remove proposal, the implementation did not ensure the LeafNode met the necessary credential criteria for the removed participant. Consequently, any party with the group's public GroupInfo could submit a Remove proposal specifying any member's LeafIndex, allowing them to evict that member and occupy their slot in the ratchet tree. This issue affected callers of the Group.externalJoin and Group.handle APIs, as the required credential check was only present in the gRPC interop harness.Recommendations
Update Bouncy Castle for Java to version 1.86 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bouncy Castle For Java