CVE-2026-71891
Received Received - Intake

BLS12-381 Public Key Validation Bypass in Bouncy Castle

Vulnerability report for CVE-2026-71891, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public key built on a foreign ECCurve that merely shares BLS12-381's field characteristic. The prime-order subgroup check trusts a point's own curve to name its cofactor, since ECPoint.satisfiesOrder returns true outright when the curve's cofactor is one, so a point on a curve with a different equation and a cofactor forged to one passed keyValidate despite not being a G1 point at all. In BC's pairing implementation such a point contributes the identity in the target group, so an aggregate signature verified against a set of public keys including it is accepted even though it contains no signature for that key and message pair, admitting a phantom signer. keyValidate now first confirms that the point's curve carries exactly the canonical G1 field, equation, order and cofactor before any subgroup check. The issue is reachable only where an application constructs an ECPoint on an explicit, non-canonical curve and accepts it as an authority-bearing key; the standard 48-byte compressed-point decoder always supplies the canonical curve and was never affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bc bc_java to 1.86 (exc)
bouncy_castle bouncy_castle to 1.86 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71891 is a flaw in Bouncy Castle Java library versions before 1.86 affecting the BLS12-381 cryptographic scheme. It allows attackers to bypass public key validation by providing a key on a manipulated curve that shares BLS12-381's field but uses different parameters. The validation incorrectly accepts such keys because it trusts the curve's cofactor without verifying the curve's equation or parameters. This enables inclusion of invalid 'phantom signers' in aggregate signatures.

Detection Guidance

To detect this vulnerability, check if your Bouncy Castle Java library version is below 1.86. Use commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle to inspect the library version in your project. If using a JAR file, inspect the manifest or run 'java -jar your-application.jar' and check the Bouncy Castle version in logs or stack traces.

Impact Analysis

If you use Bouncy Castle Java library before 1.86 with BLS12-381 signatures, an attacker could forge aggregate signatures by injecting invalid public keys. This might allow unauthorized transactions or actions if your system relies on these signatures for authentication or integrity. The attack requires your application to explicitly construct ECPoints on attacker-controlled curves, which is uncommon in standard usage.

Compliance Impact

This vulnerability could impact compliance by undermining cryptographic integrity in systems handling sensitive data. If exploited, it may allow unauthorized access or data manipulation, violating confidentiality or integrity requirements in GDPR or HIPAA. Organizations using affected Bouncy Castle versions must update to mitigate risks to compliance.

Mitigation Strategies

Upgrade Bouncy Castle to version 1.86 or later immediately. If upgrading is not possible, review your application's key validation logic to ensure it enforces canonical BLS12-381 G1 curve parameters before accepting public keys. Remove any custom ECPoint constructions that bypass standard decoders.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71891. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart