PatchSiren cyber security CVE debrief
CVE-2026-71891 Legion of the Bouncy Castle Inc. CVE debrief
PatchSiren debrief for CVE-2026-71891, a vulnerability in Bouncy Castle for Java before version 1.86, allowing phantom signers in aggregate signatures due to improper validation of public keys on non-canonical curves. The vulnerability enables attackers to bypass security measures, potentially leading to unauthorized signature forgery. Defenders should assess exposure and prioritize patching or mitigation efforts to prevent potential security breaches. The issue arises from the library's handling of public keys on non-canonical curves, which can lead to phantom signers in aggregate signatures.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for systems using Bouncy Castle for cryptographic operations should assess exposure and prioritize patching or mitigation efforts. This includes operators of systems that rely on Bouncy Castle for security, vulnerability management teams, and security teams responsible for monitoring and incident response. They should review and update cryptographic key management practices to ensure only valid, properly validated public keys are used
Why it matters
CVE-2026-71891 allows phantom signers in aggregate signatures due to improper validation of public keys on non-canonical curves in Bouncy Castle for Java before version 1.86. Defenders should prioritize patching, verify affected systems, and update cryptographic key management practices.
- Potential for unauthorized signature forgery in cryptographic operations.
- Risk of phantom signers being added to aggregate signatures.
- Need for verification of public keys used in cryptographic operations.
- Potential impact on systems relying on Bouncy Castle for security.
Technical summary
The Bouncy Castle library for Java, prior to version 1.86, contains a vulnerability in its handling of public keys on non-canonical curves, potentially allowing phantom signers in aggregate signatures. The prime-order subgroup check trusts a point's own curve to name its cofactor, since ECPoint.satisfiesOrder returns true outright when the curve's cofactor is one, so a point on a curve with a different equation and a cofactor forged to one passed keyValidate despite not being a G1 point at all. In BC's pairing implementation such a point contributes the identity in the target group, so an aggregate signature verified against a set of public keys including it is accepted even though it contains no signature for
Defensive priority
Defenders should prioritize verification of affected systems, especially those using Bouncy Castle for cryptographic operations, and apply patches or mitigations as available.
Recommended defensive actions
- Verify and apply patches for Bouncy Castle for Java version 1.86 or later.
- Review and update cryptographic key management practices to ensure only valid, properly validated public keys are used.
- Monitor systems using Bouncy Castle for potential anomalies in cryptographic operations.
- Perform a thorough review of affected systems and components to identify potential exposure.
- Implement compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence from the Bouncy Castle project and NVD indicates a vulnerability in the library's handling of public keys, potentially allowing phantom signers in certain cryptographic operations. The issue is reachable only where an application constructs an ECPoint on an explicit, non-canonical curve and accepts it as an authority-bearing key. The standard 48-byte compressed-point decoder always supplies the canonical curve and was never affected. Source confidence is limited to public statements and code review.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71891 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71891
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71891 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71891
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/c16bcfdce1f96230261b7c2c8c1e044bfc9d1deb
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071891
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.