CVE-2026-71887
Received Received - Intake

Bouncy Castle Java OpenPGP Signature Validation Flaw

Vulnerability report for CVE-2026-71887, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3 require the embedded Primary Key Binding signature on any subkey that can issue signatures; it is the subkey's own statement that it belongs to the primary key it is bound under. OpenPGPCertificate resolved the subkey's key flags two different ways. isSigningKey() goes through getKeyFlags() and getApplyingSubpacket(), which falls back to the primary key's direct-key or primary User ID self-signature when the binding signature omits the subpacket, so the subkey inherited the primary's SIGN_DATA and counted as signing-capable; verifyEmbeddedPrimaryKeyBinding(), which enforces the requirement, reads the binding signature's own hashed subpackets, found no SIGN_DATA there, and returned early as a non-signing key without ever demanding the back signature. The same subkey was therefore signing-capable - so its signatures were attributed to the certificate and OpenPGPSignature.OpenPGPDocumentSignature.isValid() returned true - while being exempt from cross-certification, where GnuPG refuses the identical certificate and message. An attacker needs only the victim's public signing subkey, which is public material: they bind it to their own primary key with a Subkey Binding signature they are able to make, carrying no Key Flags and no embedded Primary Key Binding signature, which they cannot make without the subkey's private key, and a relying party verifying one of the victim's genuinely signed messages against that certificate is told the signature is valid and given the attacker's certificate as its issuer. Because a certificate's User IDs are self-asserted, a verifier that pins on the subkey's fingerprint or key ID while taking the identity from the enclosing certificate reports a real signature under an attacker-chosen identity. This is misattribution of a genuine signature rather than forgery of a new one: no private key is recovered, and the signature must be one the grafted subkey actually made. The low-level PGPSignature / PGPPublicKeyRing API performs no binding checks by design and is unaffected. Key Flags are a statement about the key the carrying signature refers to (RFC 9580 sec. 5.2.3.29), so a subkey no longer inherits them from the certificate-wide signatures of the primary key: a Subkey Binding signature that omits the subpacket now leaves the subkey with no capabilities rather than the primary's, which makes the flags the cross-certification check consults the same flags every other decision consults. Preferences and the other subpackets a direct-key signature carries are inherited as before, and the primary key itself, whose flags legitimately come from its own direct-key or User ID self-signature, is unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
bcgit bouncy_castle to 1.86 (exc)
bcgit bouncy_castle From 1.81 (inc) to 1.86 (exc)
bouncy_castle bouncy_castle to 1.86 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71887 is a flaw in Bouncy Castle's Java library before version 1.86 affecting OpenPGP signature verification. It allows a signing subkey to be accepted without proper cross-certification, where the subkey lacks an embedded Primary Key Binding signature. This enables an attacker to bind a victim's public signing subkey to their own primary key without the required back signature, leading to misattribution of genuine signatures under the attacker's identity.

Detection Guidance

To detect this vulnerability, check if your Bouncy Castle Java library version is between 1.81 and 1.85. Use commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle to inspect the version. If the version is below 1.86, the system is vulnerable.

Impact Analysis

An attacker could exploit this to make it appear that a victim signed a message when they did not, by binding the victim's public signing subkey to the attacker's primary key. This results in misattribution of signatures, where the victim's genuine signatures are falsely attributed to the attacker's chosen identity. No private keys are recovered, but the integrity of signature attribution is compromised.

Compliance Impact

This vulnerability could undermine compliance with data integrity and non-repudiation requirements in GDPR and HIPAA. Misattributed signatures may lead to incorrect audit trails, false claims of data authenticity, or disputes over data ownership, potentially violating regulatory obligations for secure and verifiable data handling.

Mitigation Strategies

Upgrade Bouncy Castle to version 1.86 or later immediately. Replace any affected versions in your project dependencies. Review OpenPGP certificates for improperly bound subkeys and revoke or reissue them if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71887. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart