PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71889 Legion of the Bouncy Castle Inc. CVE debrief

A vulnerability in Bouncy Castle for Java before version 1.86 allows for incorrect validation of X.509 certificates, potentially leading to the acceptance of certificates that should be rejected due to NameConstraints extensions. This issue affects various versions of Bouncy Castle for Java, including the LTS version before 2.73.13 and FIPS versions before specific patches.

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for certificate validation and management in Java applications using Bouncy Castle should assess their exposure and update to version 1.86 or later. This includes operators and platforms that rely on Bouncy Castle for Java for certificate validation, as well as vulnerability management and security teams responsible for ensuring the security of certificate-based authentication and encryption.

Why it matters

Defenders should prioritize updating Bouncy Castle for Java to version 1.86 or later due to a vulnerability in certificate validation, potentially leading to the acceptance of malicious certificates.

  • Potential acceptance of malicious certificates
  • Incorrect validation of certificate paths
  • Exposure to certificate impersonation

Technical summary

The PKIXCertPathReviewer class in Bouncy Castle for Java before version 1.86 does not correctly apply X.509 name constraints to the end-entity certificate. This could lead to the acceptance of certificates that violate NameConstraints extensions imposed by the issuing CA. Affected product deployments should be reviewed for exposure, and updates to version 1.86 or later should be prioritized to mitigate potential certificate impersonation attacks. Defenders should review their certificate validation processes to ensure they are correctly handling NameConstraints extensions and verify that certificate paths are correctly validated.

Defensive priority

Defenders should prioritize updating Bouncy Castle for Java to version 1.86 or later, and review their certificate validation processes to ensure they are correctly handling NameConstraints extensions.

Recommended defensive actions

  • Update Bouncy Castle for Java to version 1.86 or later
  • Review certificate validation processes to ensure correct handling of NameConstraints extensions
  • Verify that certificate paths are correctly validated
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by the incorrect application of X.509 name constraints to the end-entity certificate in the PKIXCertPathReviewer class. This could lead to the acceptance of certificates that violate NameConstraints extensions imposed by the issuing CA.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71889 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71889

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71889 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71889

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/commit/06dcff2f51037095de126986285c998e3455ab85

    91579145-5d7b-4cc5-b925-a0262ff19630

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071889

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.