CVE-2026-71887

CVE-2026-71887 published: In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits...

View full NVD advisory → ← Back to CVE watch