PatchSiren cyber security CVE debrief
CVE-2026-71892 Legion of the Bouncy Castle Inc. CVE debrief
A vulnerability in Bouncy Castle for Java before version 1.86 allows for the acceptance of key-transport EnvelopedData or AuthEnvelopedData with a transported, HKDF-derived content-encryption key that does not match the key size of the advertised content-encryption algorithm, even when key-size validation is explicitly enabled. This issue arises from a flawed comparison in the key-size validation process for CMS key-transport recipients. The vulnerability affects Bouncy Castle for Java before 1.86 and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). Defenders handling encrypted data with HKDF-derived keys should verify the key
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders handling encrypted data with HKDF-derived keys in Bouncy Castle for Java should verify the key size of content-encryption keys and update to the latest version to mitigate this vulnerability.
Why it matters
The vulnerability in Bouncy Castle for Java allows for the acceptance of mismatched key sizes in encrypted data, potentially leading to security breaches. Defenders handling encrypted data with HKDF-derived keys should verify the key size of content-encryption keys and update to the latest version to mitigate this vulnerability.
- Defenders must verify the key size of content-encryption keys to prevent potential security risks.
- Systems handling encrypted data with HKDF-derived keys are at risk if not updated to the latest Bouncy Castle for Java version.
- The vulnerability allows for the bypass of key-size validation, potentially leading to security breaches.
Technical summary
The vulnerability arises from a flawed comparison in the key-size validation process for CMS key-transport recipients in Bouncy Castle for Java. This allows for the acceptance of key-transport EnvelopedData or AuthEnvelopedData with a transported, HKDF-derived content-encryption key that does not match the key size of the advertised content-encryption algorithm, even when key-size validation is explicitly enabled.
Defensive priority
Defenders should prioritize verifying the key size of content-encryption keys in Bouncy Castle for Java, especially in systems handling encrypted data with HKDF-derived keys.
Recommended defensive actions
- Verify the key size of content-encryption keys in Bouncy Castle for Java, especially in systems handling encrypted data with HKDF-derived keys.
- Update Bouncy Castle for Java to version 1.86 or later.
- Update Bouncy Castle for Java FIPS (BC-FJA) to bcpkix-fips 2.0.13 (2.0.X series) or 2.1.13 (2.1.X series) or later.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The issue arises from a flawed comparison between a byte array and an ASN1ObjectIdentifier, leading to a bypass of key-size validation. This affects Bouncy Castle for Java before 1.86 and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71892 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71892
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71892 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71892
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/be0a7d925c818ef2f338bcec55178b9b6336dfc3
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071892
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.