CVE-2026-71891: fallo de gravedad alta en Legion of the Bouncy Castle Inc. BC-JAVA
BLS12-381 key validation accepts a public key built on a foreign curve
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.2%
probabilidad de explotación
0.2%top 94% de las CVE
explotación observada
noninguna fuente lo reporta
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public key built on a foreign ECCurve that merely shares BLS12-381's field characteristic. The prime-order subgroup check trusts a point's own curve to name its cofactor, since ECPoint.satisfiesOrder returns true outright when the curve's cofactor is one, so a point on a curve with a different equation and a cofactor forged to one passed keyValidate despite not being a G1 point at all. In BC's pairing implementation such a point contributes the identity in the target group, so an aggregate signature verified against a set of public keys including it is accepted even though it contains no signature for that key and message pair, admitting a phantom signer. keyValidate now first confirms that the point's curve carries exactly the canonical G1 field, equation, order and cofactor before any subgroup check. The issue is reachable only where an application constructs an ECPoint on an explicit, non-canonical curve and accepts it as an authority-bearing key; the standard 48-byte compressed-point decoder always supplies the canonical curve and was never affected.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Productos afectados
Legion of the Bouncy Castle Inc. · BC-JAVACVEs relacionadas — Legion of the Bouncy Castle Inc. BC-JAVA
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-5598HIGHNon-constant time comparisons risk private key leakage in FrodoKEM.EPSS 1.0%CVE-2026-3505HIGHUnbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.EPSS 0.9%CVE-2026-5588MEDIUMPKIX draft CompositeVerifier accepts empty signature sequence as valid.EPSS 0.7%CVE-2026-58060HIGHHSS public-key level count unbounded, enabling huge allocation on verifyEPSS 0.6%CVE-2026-59646HIGHDTLS handshake reassembler allocates buffer from unchecked 24-bit lengthEPSS 0.6%CVE-2026-0636MEDIUMLDAP Injection Vulnerability in LDAPStoreHelper.javaEPSS 0.5%