PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71892 Legion of the Bouncy Castle Inc. CVE debrief

A vulnerability in Bouncy Castle for Java before version 1.86 allows for the acceptance of key-transport EnvelopedData or AuthEnvelopedData with a transported, HKDF-derived content-encryption key that does not match the key size of the advertised content-encryption algorithm, even when key-size validation is explicitly enabled. This issue arises from a flawed comparison in the key-size validation process for CMS key-transport recipients. The vulnerability affects Bouncy Castle for Java before 1.86 and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). Defenders handling encrypted data with HKDF-derived keys should verify the key

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders handling encrypted data with HKDF-derived keys in Bouncy Castle for Java should verify the key size of content-encryption keys and update to the latest version to mitigate this vulnerability.

Why it matters

The vulnerability in Bouncy Castle for Java allows for the acceptance of mismatched key sizes in encrypted data, potentially leading to security breaches. Defenders handling encrypted data with HKDF-derived keys should verify the key size of content-encryption keys and update to the latest version to mitigate this vulnerability.

  • Defenders must verify the key size of content-encryption keys to prevent potential security risks.
  • Systems handling encrypted data with HKDF-derived keys are at risk if not updated to the latest Bouncy Castle for Java version.
  • The vulnerability allows for the bypass of key-size validation, potentially leading to security breaches.

Technical summary

The vulnerability arises from a flawed comparison in the key-size validation process for CMS key-transport recipients in Bouncy Castle for Java. This allows for the acceptance of key-transport EnvelopedData or AuthEnvelopedData with a transported, HKDF-derived content-encryption key that does not match the key size of the advertised content-encryption algorithm, even when key-size validation is explicitly enabled.

Defensive priority

Defenders should prioritize verifying the key size of content-encryption keys in Bouncy Castle for Java, especially in systems handling encrypted data with HKDF-derived keys.

Recommended defensive actions

  • Verify the key size of content-encryption keys in Bouncy Castle for Java, especially in systems handling encrypted data with HKDF-derived keys.
  • Update Bouncy Castle for Java to version 1.86 or later.
  • Update Bouncy Castle for Java FIPS (BC-FJA) to bcpkix-fips 2.0.13 (2.0.X series) or 2.1.13 (2.1.X series) or later.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The issue arises from a flawed comparison between a byte array and an ASN1ObjectIdentifier, leading to a bypass of key-size validation. This affects Bouncy Castle for Java before 1.86 and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71892 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71892

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71892 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71892

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/commit/be0a7d925c818ef2f338bcec55178b9b6336dfc3

    91579145-5d7b-4cc5-b925-a0262ff19630

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071892

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.