CVE-2026-17507
Received Received - Intake

Bouncy Castle Java MLS Integer Overflow

Vulnerability report for CVE-2026-17507, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate encoding rather than malformed input, and it must still decode, since the MLS interop test vectors round-trip the full range. GroupKeySet.SecretTree.hasLeaf and Group.validateRemove compared the decoded value directly against the tree's leaf count, and a signed comparison treats any negative int as less than a positive bound, so an out-of-range sender passed the membership check. In the hasLeaf case the SenderData of an unprotected PrivateMessage could then drive LeafIndex.directPath through NodeIndex.parent() arithmetic that never reaches the tree root, growing the resulting node list without bound until the JVM exhausted its heap. A single small message from any current group member could therefore deny service to every other member of the group. Both comparisons now interpret the value as unsigned via Integer.toUnsignedLong, rejecting an out-of-range sender however it was encoded; well-formed leaf indices are unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
org.bouncycastle bouncy_castle to 1.86 (exc)
bouncy_castle bc_java to 1.86 (exc)
bouncy_castle bc_java From 1.73 (inc) to 1.86 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-195 The product uses a signed primitive and performs a cast to an unsigned primitive, which can produce an unexpected value if the value of the signed primitive can not be represented using an unsigned primitive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-17507 is a vulnerability in Bouncy Castle for Java before version 1.86 affecting the Messaging Layer Security (MLS) implementation. It involves a leaf_index parameter defined as a uint32 in RFC 9420 but stored as a signed integer in BC's code. This causes wire values with the top bit set to decode as negative numbers, which are valid but trigger incorrect membership checks. The vulnerability allows an attacker to bypass validation and trigger a denial-of-service by exhausting JVM heap memory.

Detection Guidance

This vulnerability is specific to applications using Bouncy Castle Java library versions 1.73 to 1.85. To detect it, check the version of Bouncy Castle in your Java application dependencies. If you are using Maven, run: mvn dependency:tree | grep bouncycastle. If the version is between 1.73 and 1.85, the system is potentially vulnerable.

Impact Analysis

This vulnerability allows any current group member to send a single small message that causes a denial-of-service for all other members in the group. The attack exploits incorrect integer comparison to manipulate the system into an infinite loop, consuming all available heap memory on the JVM. This can disrupt services relying on the Bouncy Castle MLS implementation.

Compliance Impact

This vulnerability primarily causes a denial-of-service condition by exhausting JVM heap memory, which could disrupt availability of services handling sensitive data. For GDPR, this may impact availability of personal data processing systems, potentially violating Article 32 requirements for resilience. For HIPAA, it could affect the availability of electronic protected health information systems, potentially compromising the Security Rule's integrity and availability requirements.

Mitigation Strategies

Upgrade the Bouncy Castle Java library to version 1.86 or later. This version includes the fix for the leaf_index handling issue. If upgrading is not immediately possible, consider disabling the MLS functionality in Bouncy Castle if it is not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17507. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart