CVE-2026-71885: CWE-295 Improper Certificate Validation in Legion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-71885 is a critical vulnerability in Bouncy Castle for Java versions before 1.86 affecting the Messaging Layer Security (MLS) implementation. The flaw involves improper certificate validation where the X.509 certificate chain is not properly bound to the LeafNode's signature key, allowing an attacker to impersonate another party's identity. This can lead to unauthorized admission to a group, eviction of legitimate members, and decryption and injection of group messages. The issue is fixed by requiring the end-entity certificate's public key to match the signature key as specified by RFC 9420. Deployments using only basic credentials are not affected.
AI Analysis
Technical Summary
In Bouncy Castle for Java prior to version 1.86, the MLS implementation did not enforce that the X.509 certificate's public key matched the LeafNode's signature_key as required by RFC 9420 section 5.3. The LeafNode.verify() method validated signatures against the signature_key in the leaf itself but did not parse or validate the certificate chain, allowing an attacker to present a certificate belonging to another party while signing with an unrelated key. This flaw enables an unauthenticated attacker, in deployments that allow external commits without independent credential checks, to impersonate a victim's X.509 identity, evict the victim from the group, derive the current epoch, decrypt subsequent messages, and send messages accepted as the victim. The fix in version 1.86 enforces that the certificate's subject public key matches the signature_key and rejects leaves with invalid or empty certificate chains. Certificate chain validation to a trust anchor remains the responsibility of the application as per RFC 9420 section 5.3.1. Deployments using only basic credentials are unaffected.
Potential Impact
An unauthenticated attacker can impersonate another party's identity within an MLS group, evict legitimate members, decrypt future group messages, and inject messages accepted as the victim. This compromises confidentiality, integrity, and authentication of group communications in affected deployments that admit external commits without independent credential admission checks.
Mitigation Recommendations
A fix is available in Bouncy Castle for Java version 1.86 that enforces proper binding of the X.509 certificate's public key to the LeafNode's signature_key. Users should upgrade to version 1.86 or later. Deployments using only basic credentials are not affected. Certificate chain validation remains the responsibility of the application per RFC 9420. No additional vendor advisory is provided; check the vendor's official resources for updates.
CVE-2026-71885: CWE-295 Improper Certificate Validation in Legion of the Bouncy Castle Inc. BC-JAVA
Description
CVE-2026-71885 is a critical vulnerability in Bouncy Castle for Java versions before 1.86 affecting the Messaging Layer Security (MLS) implementation. The flaw involves improper certificate validation where the X.509 certificate chain is not properly bound to the LeafNode's signature key, allowing an attacker to impersonate another party's identity. This can lead to unauthorized admission to a group, eviction of legitimate members, and decryption and injection of group messages. The issue is fixed by requiring the end-entity certificate's public key to match the signature key as specified by RFC 9420. Deployments using only basic credentials are not affected.
CVSS v4.0
Score 9.2critical
Affected software
Legion of the Bouncy Castle Inc.
BC-JAVA
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Bouncy Castle for Java prior to version 1.86, the MLS implementation did not enforce that the X.509 certificate's public key matched the LeafNode's signature_key as required by RFC 9420 section 5.3. The LeafNode.verify() method validated signatures against the signature_key in the leaf itself but did not parse or validate the certificate chain, allowing an attacker to present a certificate belonging to another party while signing with an unrelated key. This flaw enables an unauthenticated attacker, in deployments that allow external commits without independent credential checks, to impersonate a victim's X.509 identity, evict the victim from the group, derive the current epoch, decrypt subsequent messages, and send messages accepted as the victim. The fix in version 1.86 enforces that the certificate's subject public key matches the signature_key and rejects leaves with invalid or empty certificate chains. Certificate chain validation to a trust anchor remains the responsibility of the application as per RFC 9420 section 5.3.1. Deployments using only basic credentials are unaffected.
Potential Impact
An unauthenticated attacker can impersonate another party's identity within an MLS group, evict legitimate members, decrypt future group messages, and inject messages accepted as the victim. This compromises confidentiality, integrity, and authentication of group communications in affected deployments that admit external commits without independent credential admission checks.
Mitigation Recommendations
A fix is available in Bouncy Castle for Java version 1.86 that enforces proper binding of the X.509 certificate's public key to the LeafNode's signature_key. Users should upgrade to version 1.86 or later. Deployments using only basic credentials are not affected. Certificate chain validation remains the responsibility of the application per RFC 9420. No additional vendor advisory is provided; check the vendor's official resources for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- bcorg
- Date Reserved
- 2026-08-08T00:06:06.982Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac0c475a43b0b3b89b22f89
Added to database: 10/03/2026, 09:01:41 UTC
Last enriched: 10/03/2026, 09:16:08 UTC
Last updated: 10/03/2026, 14:46:10 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.