CVE-2026-71885

CVE-2026-71885 published: In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf its...

View full NVD advisory → ← Back to CVE watch