Executive brief
Bouncy Castle is a widely used Java library that provides cryptographic functions for securing data and communications. A vulnerability in its certificate handling module allows certain digital signatures to be incorrectly treated as valid even when they are empty. This could potentially allow an attacker to bypass security checks in applications that rely on these specific composite signature types for authentication or data integrity.
Technical details
A vulnerability exists in the Bouncy Castle Java PKIX modules (BC-JAVA, BCPKIX-FIPS, and BCPKIX-LTS) within the JcaContentVerifierProviderBuilder.java component. The implementation of the early draft COMPOSITE signature type fails to verify that at least one signature is present in a sequence. Consequently, the CompositeVerifier treats an empty signature sequence as valid. An attacker could exploit this to bypass signature verification requirements in systems utilizing these draft composite signatures. The issue is resolved by ensuring the verifier checks that at least one signature has been validated.
Affected products
- Bouncy Castle BC-JAVA bcpkix 1.67 to 1.80.1, 1.81, 1.82 to 1.83
- Bouncy Castle BCPKIX-FIPS bcpkix 2.0.6 to 2.0.10, 2.1.7 to 2.1.10
- Bouncy Castle BCPKIX-LTS bcpkix 2.73.7 to 2.73.10
Timeline
- 2026-04-05: patched: Fix committed to bc-java repository
- 2026-04-15: advisory: Initial advisory published
- 2026-05-18: other: Advisory updated with expanded version impact and LTS details