Skip to main content
EPSS 0.2%top 85%

In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list,… (CVE-2026-71890)

0
High
Published: 10/03/2026 (10/03/2026, 09:31:18 UTC)
Source: GCVE Database

Description

A vulnerability in Bouncy Castle for Java before version 1.86 allows improper validation of MLS external commit proposal lists. This flaw permits an attacker with access to the group's public GroupInfo to submit a Remove proposal evicting any member and taking over their slot in the ratchet tree. The issue arises because the validation did not verify that the removed leaf corresponded to the joiner, missing a critical credential check. The vulnerability is addressed by requiring the removed leaf's credential to match the joiner's new leaf credential on both sending and receiving sides.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
Scope
X
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

Affected software

org.bouncycastle/bcprov-jdk15on
pkg:maven/org.bouncycastle/bcprov-jdk15on
Affected versions
<1.86

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:29:59 UTC

Technical Analysis

In Bouncy Castle for Java versions prior to 1.86, the method org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals failed to properly validate the relationship between a Remove proposal's removed leaf and the joiner in MLS external commits as defined by RFC 9420. Specifically, it allowed any party with the group's public GroupInfo to submit a Remove proposal targeting any member's LeafIndex, causing that member's eviction and the attacker taking over their ratchet tree slot. The missing credential check, which should have ensured the removed leaf's credential matched the joiner's new leaf credential, was only present in the gRPC interop harness and not in the public API. The fix enforces this credential check on both sending and receiving ends, preventing unauthorized removals.

Potential Impact

An unauthenticated attacker with access to the group's public GroupInfo can evict arbitrary group members by submitting a malicious Remove proposal in an external commit. This allows the attacker to take over the evicted member's position in the ratchet tree, potentially compromising group membership integrity and security. The vulnerability undermines the MLS protocol's protections against unauthorized removals in external joins.

Mitigation Recommendations

A fix is available in Bouncy Castle for Java version 1.86 that enforces the required credential check for Remove proposals in external commits. Users should upgrade to version 1.86 or later to mitigate this vulnerability. No other mitigation is indicated or required according to the available information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-jc55-7frr-fv5r
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71890"]
Database Specific Severity
HIGH
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac1397ba43b0b3b89d63c7a

Added to database: 10/03/2026, 17:20:59 UTC

Last enriched: 10/03/2026, 17:29:59 UTC

Last updated: 10/04/2026, 02:46:06 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses