CVE-2026-71890

CVE-2026-71890 published: In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the removed leaf index but never establish...

View full NVD advisory → ← Back to CVE watch