CVE-2026-71888
Received Received - Intake

Authenticated-Data Parser Flaw in Bouncy Castle Java

Vulnerability report for CVE-2026-71888, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2 makes the MAC cover the DER encoding of authAttrs when they are present and the eContent OCTET STRING directly when they are not. CMSAuthenticatedDataParser has to choose between those two in its constructor, before it can reach authAttrs, which comes later in the SEQUENCE, so it chose on digestAlgorithm alone: for a message with digestAlgorithm absent but authAttrs present it verified the content MAC and then returned the attributes through getAuthAttrs() as though they had been authenticated, when the MAC had never covered them. An attacker able to modify a message in transit could insert an authenticated attribute, such as an RFC 2634 ESSSecurityLabel, into an otherwise valid message while holding neither the key-encryption key nor the content-MAC key, and an application taking an authorization, routing or labelling decision from those attributes would act on attacker-chosen values. The content itself remained MAC-bound. asn1.cms.AuthenticatedData now rejects the mismatched pairing when parsing and CMSAuthenticatedDataParser cross-checks the two fields once authAttrs is read. This is a variant of CVE-2026-59642, which bound the content to the MAC for messages that legitimately carry authAttrs, and which does not address this case. This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), and bcutil-fips 2.0.8 (2.0.X series) and 2.1.8 (2.1.X series).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
bouncy_castle bc_java to 1.86 (exc)
bouncy_castle bc_lts to 2.73.13 (exc)
bouncy_castle bc_fja to 2.1.13 (exc)
bouncy_castle bcutil_fja to 2.1.8 (exc)
bouncy_castle bouncy_castle to 1.86 (exc)
bouncy_castle bouncy_castle_lts to 2.73.13 (exc)
bouncy_castle bouncy_castle_fips to 1.0.13 (exc)
bouncy_castle bouncy_castle_fips to 2.0.13 (exc)
bouncy_castle bouncy_castle_fips to 2.1.13 (exc)
bouncy_castle bcutil_fips to 2.0.8 (exc)
bouncy_castle bcutil_fips to 2.1.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71888 is a vulnerability in Bouncy Castle's Java library affecting CMS AuthenticatedData parsing. It occurs when a message has a mismatch between the digestAlgorithm field and authAttrs field, violating RFC 5652. The parser incorrectly verified messages based only on digestAlgorithm, allowing attackers to insert authenticated attributes into valid messages without proper authentication. Applications relying on these attributes for security decisions could be tricked into processing attacker-controlled values.

The issue allows an attacker to modify a valid message by adding authAttrs where digestAlgorithm is absent. Since the MAC does not cover these attributes, they are not authenticated. The content itself remains protected by the MAC, but the inserted attributes can influence security decisions in applications.

Detection Guidance

To detect this vulnerability, inspect Bouncy Castle Java library versions. Check if using bc-java before 1.86, BC-LTS before 2.73.13, or BC-FJA/bcutil-FJA before specified FIPS versions. Review CMS AuthenticatedData messages for mismatched digestAlgorithm and authAttrs fields. Use tools like OWASP Dependency Check or Maven/Gradle to verify library versions.

Impact Analysis

If you use Bouncy Castle's Java library in versions before 1.86, BC-LTS before 2.73.13, or BC-FJA/bcutil-FJA before specific FIPS versions, your application could be vulnerable. Attackers could insert malicious authenticated attributes into CMS messages, potentially leading to incorrect authorization, routing, or labeling decisions based on attacker-controlled values.

Applications that rely on authenticated attributes for security decisions, such as ESSSecurityLabel, could be misled. While the content remains protected, the misuse of attributes could result in unauthorized actions or data exposure if the application trusts these attributes.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to authenticated attributes in CMS messages. If an application relies on these attributes for access control or data handling decisions, it may violate GDPR's integrity and confidentiality principles or HIPAA's security requirements for protecting sensitive data.

Organizations using affected Bouncy Castle versions must update to patched versions to ensure proper validation of authenticated attributes. Failure to address this could result in non-compliance with data protection regulations due to potential unauthorized attribute manipulation.

Mitigation Strategies
  • Upgrade Bouncy Castle Java libraries to versions 1.86 or later for bc-java, 2.73.13 or later for BC-LTS, and the specified FIPS versions for BC-FJA/bcutil-FJA.
  • Review applications using CMS AuthenticatedData to ensure they do not rely solely on authAttrs for security decisions without proper validation.
  • Monitor network traffic for CMS AuthenticatedData messages with mismatched digestAlgorithm and authAttrs fields, as these may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71888. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart