CVE-2026-71892
Received Received - Intake

Key Size Validation Bypass in Bouncy Castle for Java

Vulnerability report for CVE-2026-71892, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption key derivation (id-alg-cek-hkdf-sha256). The branch that should have selected the actual content-encryption algorithm carried in the key derivation AlgorithmIdentifier's parameters compared the encrypted-key byte array against the id-alg-cek-hkdf-sha256 object identifier, a comparison between a byte array and an ASN1ObjectIdentifier that is false for every possible input, so the check fell through to a key-size lookup on the outer wrapper OID. That OID identifies a key-derivation construction rather than a cipher and has no registered key size, so the size comparison was skipped entirely. A key-transport EnvelopedData or AuthEnvelopedData whose transported, HKDF-derived content-encryption key did not match the key size of the advertised content-encryption algorithm was therefore accepted even with validation explicitly enabled, silently defeating the only mechanism the API offers for enforcing recovered key size. The recipient now dispatches on the content-encryption AlgorithmIdentifier's algorithm OID, so validation checks the recovered key against the inner content-encryption algorithm. Messages with a matching key size, non-HKDF messages, and recipients that do not enable validation are unaffected. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
bouncy_castle bouncy_castle 1.86
bouncy_castle bcpkix_fips From 2.0.7 (inc)
bouncy_castle bcpkix_fips 2.1.13
org.bouncycastle bouncy_castle to 1.86 (exc)
org.bouncycastle bouncy_castle_fips to 2.0.13 (exc)
org.bouncycastle bouncy_castle_fips to 2.1.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-697 The product compares two entities in a security-relevant context, but the comparison is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71892 is a flaw in Bouncy Castle Java libraries before version 1.86 and BC-FJA bcpkix-fips before versions 2.0.13 and 2.1.13. It involves incorrect key-size validation for CMS key-transport recipients using RFC 9709 HKDF-derived keys. The validation logic fails to properly unwrap the content-encryption algorithm identifier, causing it to skip checks against the actual cipher algorithm. This allows recipients with validation enabled to accept mismatched key sizes silently.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle Java libraries before version 1.86 or BC-FJA bcpkix-fips before versions 2.0.13 or 2.1.13. Inspect the library versions in your project dependencies or runtime environment. No specific commands are provided in the context for detection.

Impact Analysis

An attacker could exploit this by advertising a stronger encryption algorithm while transporting a weaker key. A recipient with key-size validation enabled would still accept the weaker key, bypassing an explicitly requested security policy. While plaintext isn't directly exposed, this undermines enforced security controls, potentially allowing unauthorized data access or manipulation.

Compliance Impact

This vulnerability could impact compliance by failing to enforce required encryption key sizes, violating policies for data protection. Organizations relying on Bouncy Castle for secure communications may inadvertently violate GDPR's data integrity requirements or HIPAA's encryption standards if key-size validation is bypassed.

Mitigation Strategies

Immediately upgrade Bouncy Castle Java libraries to version 1.86 or later. For BC-FJA bcpkix-fips, upgrade to versions 2.0.13 or 2.1.13. If using RFC 9709 HKDF-derived keys, ensure key-size validation is enabled and verify the fix addresses the OID comparison issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71892. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart