CVE-2026-71887
CVE-2026-71887 — OpenPGP data signature accepted from a signing subkey without cross-certification
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3 require the embedded Primary Key Binding signature on any subkey that can issue signatures; it is the subkey's own statement that it belongs to the primary key it is bound under. OpenPGPCertificate resolved the subkey's key flags two different ways. isSigningKey() goes through getKeyFlags() and getApplyingSubpacket(), which falls back to the primary key's direct-key or primary User ID self-signature when the binding signature omits the subpacket, so the subkey inherited the primary's SIGN_DATA and counted as signing-capable; verifyEmbeddedPrimaryKeyBinding(), which enforces the requirement, reads the binding signature's own hashed subpackets, found no SIGN_DATA there, and returned early as a non-signing key without ever demanding the back signature. The same subkey was therefore signing-capable - so its signatures were attributed to the certificate and OpenPGPSignature.OpenPGPDocumentSignature.isValid() returned true - while being exempt from cross-certification, where GnuPG refuses the identical certificate and message. An attacker needs only the victim's public signing subkey, which is public material: they bind it to their own primary key with a Subkey Binding signature they are able to make, carrying no Key Flags and no embedded Primary Key Binding signature, which they cannot make without the subkey's private key, and a relying party verifying one of the victim's genuinely signed messages against that certificate is told the signature is valid and given the attacker's certificate as its issuer. Because a certificate's User IDs are self-asserted, a verifier that pins on the subkey's fingerprint or key ID while taking the identity from the enclosing certificate reports a real signature under an attacker-chosen identity. This is misattribution of a genuine signature rather than forgery of a new one: no private key is recovered, and the signature must be one the grafted subkey actually made. The low-level PGPSignature / PGPPublicKeyRing API performs no binding checks by design and is unaffected. Key Flags are a statement about the key the carrying signature refers to (RFC 9580 sec. 5.2.3.29), so a subkey no longer inherits them from the certificate-wide signatures of the primary key: a Subkey Binding signature that omits the subpacket now leaves the subkey with no capabilities rather than the primary's, which makes the flags the cross-certification check consults the same flags every other decision consults. Preferences and the other subpackets a direct-key signature carries are inherited as before, and the primary key itself, whose flags legitimately come from its own direct-key or User ID self-signature, is unaffected.
Published Updated Sources: NVD, Legion of the Bouncy Castle Inc. (CNA), GitHub, GitHub Security Advisory, SOCRadar CTI
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Exploit code
public exploit, none observed
EPSS
0%
ahead of 0% of scored CVEs
CVSS base
8.2
high
Remediation
The vendor's own words where we have them.
Upgrade BC-JAVA to a fixed release. Apply vendor patches per advisory and restrict external exposure of the affected component until patched.
First 24 hours
Ordered from the record's own fields — exposure first, because you cannot patch what you have not found.
- Identify exposed assets running affected vendor/product/version combinations.
- Prioritize based on EPSS, PoC availability, and external exposure.
- Search available logs for exploit probes, errors, authentication anomalies, or suspicious child processes matching the vulnerability class.
Affected scope
Vendor, product and version as the advisories word them.
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 1.81 to < 1.86 | Vulnerable |
Attack characteristics
The CVSS vector, decoded. It describes the attack, not your exposure to it.
Scope
X
Attack Complexity
Low
Attack Vector
Network
Privileges Req
None
User Interaction
None
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 8.2 | CVSS 4.0 | high | — | — | Legion of the Bouncy Castle Inc. (CNA) |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
What this weakness leads to
MITRE's own consequences and mitigations for the weakness class — the authority's wording, not guidance derived from the CVSS vector.
CWE-345 · Insufficient Verification of Data Authenticity
- Varies by Context
- Unexpected State::
CWE-347 · Improper Verification of Cryptographic Signature
- Gain Privileges or Assume Identity
- Modify Application Data
- Execute Unauthorized Code or Commands
Weakness & attack patterns
- CWE-347
- CWE-345
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1557.002Adversary-in-the-Middle: ARP Cache Poisoning
- T1584.002Compromise Infrastructure: DNS Server
- T1491Defacement
Public exploit
Capability, not use: code existing is a different claim from anyone running it.
Repositories
2
Detection
Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.
- Prioritize edge telemetry for network-reachable BC-JAVA.
- Monitor for scanner or exploit-pattern traffic after 2 public PoC repositories were reported.
Timeline
What happened to this CVE, newest first — with the readings a source repeats on a schedule counted underneath rather than listed.
- 2026
Added · CVSS 3.1 8.2 (AV:N)
Oct 3, 2026 · NVD
Initial · CVE published
Oct 3, 2026 · NVD
Added · GHSA-cwf6-pghv-hq93 published (high)
Oct 3, 2026 · GitHub Security Advisory
CVE published by MITRE.
Oct 3, 2026 · SOCRadar CTI
Source activity
Readings a source repeats on a schedule, counted rather than listed.
- 1×CVE modified by NIST: CWE updated.Oct 3, 2026 · SOCRadar CTI
References
4 on the record
- github.com/bcgit/bc-java/commit/b51452fa48ccb578fc16b8222fce9eedf92c94d6
Exploit, Third Party Advisory, NIST
- github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071887
Exploit, Third Party Advisory, NIST
- nvd.nist.gov/vuln/detail/CVE-2026-71887
NVD
- github.com/advisories/GHSA-cwf6-pghv-hq93
Exploit, Third Party Advisory
Elsewhere on this site
- Legion of the Bouncy Castle Inc.every CVE for this vendor
- Unclassifiedsame class
- CWE-347other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.
Answered from this record1
What should defenders know first?
CVE-2026-71887 is OpenPGP data signature accepted from a signing subkey without cross-certification, a high vulnerability affecting BC-JAVA from Legion of the Bouncy Castle Inc.. The current evidence does not list it in CISA KEV, and the exploit status is: Active exploitation is not confirmed from current sources for CVE-2026-71887. Public exploit evidence is: 2 public PoC repositories reported; 0 marked weaponized in current dataset. The affected-version evidence is listed in the key facts and affected products tables. Defenders should first verify whether exposed or business-critical assets run those versions, then apply vendor patches or mitigations, restrict reachable attack surface, and preserve logs for detection review. CVSS 8.2 describes technical severity, while EPSS 0% helps estimate near-term exploit likelihood; neither replaces asset context. Unknown fields should remain explicit in tickets, and threat actor, IOC, victimology, or payload claims should not be added unless a cited source supports them. Monitor CISA KEV, vendor advisories, NVD changes, public PoC repositories, and internal telemetry for update triggers.