Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-71892
Published:October 03, 2026
Updated:October 11, 2026
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption key derivation (id-alg-cek-hkdf-sha256). The branch that should have selected the actual content-encryption algorithm carried in the key derivation AlgorithmIdentifier's parameters compared the encrypted-key byte array against the id-alg-cek-hkdf-sha256 object identifier, a comparison between a byte array and an ASN1ObjectIdentifier that is false for every possible input, so the check fell through to a key-size lookup on the outer wrapper OID. That OID identifies a key-derivation construction rather than a cipher and has no registered key size, so the size comparison was skipped entirely. A key-transport EnvelopedData or AuthEnvelopedData whose transported, HKDF-derived content-encryption key did not match the key size of the advertised content-encryption algorithm was therefore accepted even with validation explicitly enabled, silently defeating the only mechanism the API offers for enforcing recovered key size. The recipient now dispatches on the content-encryption AlgorithmIdentifier's algorithm OID, so validation checks the recovered key against the inner content-encryption algorithm. Messages with a matching key size, non-HKDF messages, and recipients that do not enable validation are unaffected. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
Affected Packages
https://github.com/bcgit/bc-lts-java.git (GITHUB):
Affected version(s) >=r2rv73dot6 <r2rv73dot13
Fix Suggestion:
Update to version r2rv73dot13
https://github.com/bcgit/bc-java.git (GITHUB):
Affected version(s) >=r1rv78 <r1rv86
Fix Suggestion:
Update to version r1rv86
org.bouncycastle:bcpkix-debug-jdk18on (JAVA):
Affected version(s) >=1.78 <1.86
Fix Suggestion:
Update to version 1.86
org.bouncycastle:bcpkix-lts8on (JAVA):
Affected version(s) >=2.73.6 <2.73.13
Fix Suggestion:
Update to version 2.73.13
org.bouncycastle:bcpkix-fips (JAVA):
Affected version(s) >=2.0.7 <2.0.13
Fix Suggestion:
Update to version 2.0.13
org.bouncycastle:bcpkix-debug-jdk15to18 (JAVA):
Affected version(s) >=1.78 <1.86
Fix Suggestion:
Update to version 1.86
org.bouncycastle:bcpkix-jdk14 (JAVA):
Affected version(s) >=1.78 <1.86
Fix Suggestion:
Update to version 1.86
org.bouncycastle:bcpkix-jdk18on (JAVA):
Affected version(s) >=1.78 <1.86
Fix Suggestion:
Update to version 1.86
org.bouncycastle:bcpkix-jdk15to18 (JAVA):
Affected version(s) >=1.78 <1.86
Fix Suggestion:
Update to version 1.86
org.bouncycastle:bcpkix-fips (JAVA):
Affected version(s) >=2.1.8 <2.1.13
Fix Suggestion:
Update to version 2.1.13
Do you need more information?
Contact Us
CVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
Incorrect Comparison
EPSS
Base Score:
0.17