PatchSiren cyber security CVE debrief
CVE-2026-71889 Legion of the Bouncy Castle Inc. CVE debrief
A vulnerability in Bouncy Castle for Java before version 1.86 allows for incorrect validation of X.509 certificates, potentially leading to the acceptance of certificates that should be rejected due to NameConstraints extensions. This issue affects various versions of Bouncy Castle for Java, including the LTS version before 2.73.13 and FIPS versions before specific patches.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for certificate validation and management in Java applications using Bouncy Castle should assess their exposure and update to version 1.86 or later. This includes operators and platforms that rely on Bouncy Castle for Java for certificate validation, as well as vulnerability management and security teams responsible for ensuring the security of certificate-based authentication and encryption.
Why it matters
Defenders should prioritize updating Bouncy Castle for Java to version 1.86 or later due to a vulnerability in certificate validation, potentially leading to the acceptance of malicious certificates.
- Potential acceptance of malicious certificates
- Incorrect validation of certificate paths
- Exposure to certificate impersonation
Technical summary
The PKIXCertPathReviewer class in Bouncy Castle for Java before version 1.86 does not correctly apply X.509 name constraints to the end-entity certificate. This could lead to the acceptance of certificates that violate NameConstraints extensions imposed by the issuing CA. Affected product deployments should be reviewed for exposure, and updates to version 1.86 or later should be prioritized to mitigate potential certificate impersonation attacks. Defenders should review their certificate validation processes to ensure they are correctly handling NameConstraints extensions and verify that certificate paths are correctly validated.
Defensive priority
Defenders should prioritize updating Bouncy Castle for Java to version 1.86 or later, and review their certificate validation processes to ensure they are correctly handling NameConstraints extensions.
Recommended defensive actions
- Update Bouncy Castle for Java to version 1.86 or later
- Review certificate validation processes to ensure correct handling of NameConstraints extensions
- Verify that certificate paths are correctly validated
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by the incorrect application of X.509 name constraints to the end-entity certificate in the PKIXCertPathReviewer class. This could lead to the acceptance of certificates that violate NameConstraints extensions imposed by the issuing CA.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71889 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71889
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71889 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71889
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/06dcff2f51037095de126986285c998e3455ab85
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071889
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.