Intel

AIKIDO-2026-112898

bcmls-jdk18on is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2026-71885 Published Yesterday

85

High Risk

This Affects:

JAVAbcmls-jdk18on
1.78 - 1.85
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

MLS verifies a LeafNode with its declared signature key without checking that the key matches the public key in its X.509 credential, so a member identity can be paired with an unrelated signing key. The fix parses the end-entity certificate key and compares it with the MLS signature_key.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your MLS deployment accepts X.509 credentials and relies on Bouncy Castle to bind a member identity to its LeafNode signing key.

Background info

bcmls-jdk18on is vulnerable to Improper Certificate Validation in versions 1.78 - 1.85.

How to fix this

Upgrade the bcmls-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform