Bouncy Castle for Java CVE-2026-71885 (CVSS 4.0 9.2): MLS X.509 credential not bound to leaf signature key — impersonate a group member; fix 1.86
NVD record CVE-2026-71885 (published 3 October 2026; CNA CVSS 4.0 9.2 Critical; CWE-287 / CWE-295) and the Legion of the Bouncy Castle advisory page: the Messaging Layer Security (MLS, RFC 9420) implementation in Bouncy Castle for Java before 1.86 never tied an X.509 credential to the LeafNode signature_key. LeafNode.verify() checked the leaf's signature against the key carried in the leaf itself, and the credential's certificate chain was stored but never parsed or compared, so RFC 9420 section 5.3's binding was not enforced. A party could present someone else's certificate as its credential and sign the leaf and KeyPackage with an unrelated key, and be accepted under that person's identity. Where a deployment publishes GroupInfo and the ratchet tree for external joins and passes external commits to Group.handle() without its own credential-admission check, an unauthenticated attacker could join as the victim, evict them, derive the current epoch, read later group messages, and send messages accepted as the victim. Deployments using only basic credentials are unaffected. Fixed in 1.86 (commit 77632a57ed; bcmls-jdk18on 1.86 on Maven Central): the leaf is rejected unless the end-entity certificate's public key equals signature_key; chain and identity validation to a trust anchor remain the application's job. Credit: Joshua Rogers and Khaled Suliman (AISLE Research). No exploitation reported; no Australian-specific notice found. Wire pickup: Forkast 4 Oct.
- Product
- Bouncy Castle for Java — MLS (RFC 9420) implementation (bcmls-jdk18on), X.509 credentials
- Versions
- Affected: Bouncy Castle for Java before 1.86 (Java 8 and later), MLS deployments using X.509 credentials. Basic-credential-only deployments unaffected.
- CVSS
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N- Exploited in Australia?
- unknown
- Patch to
- Upgrade Bouncy Castle for Java to 1.86 (bcmls-jdk18on and matching bcprov/bcpkix 1.86). Until upgraded: do not accept external commits without an independent credential-admission check, and validate that each member's certificate key matches its MLS signature key in application code. After upgrade, keep certificate-chain and identity validation to your trust anchor in the application, as RFC 9420 5.3.1 requires.
Primary: Bouncy Castle (bc-java wiki) — CVE-2026-71885 MLS X.509 credential binding · Vendor: bcgit/bc-java — fix commit 77632a57ed · CVE: CVE-2026-71885 · NVD — CVE-2026-71885 (published 3 Oct 2026)
