Intel

AIKIDO-2026-322957

bcprov-jdk18on is vulnerable to Signature Verification Bypass

Signature Verification BypassCVE-2026-71891 Published Yesterday

45

Medium Risk

This Affects:

JAVAbcprov-jdk18on
1.85 - 1.85.2
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

BLS12-381 public-key validation accepts a point on a foreign curve that shares the field characteristic, so a phantom signer can appear in an aggregate signature. The fix requires the exact canonical BLS12-381 G1 curve before the subgroup and order check.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you directly construct BLS public-key points on explicit curves and rely on aggregate-signature participant validation.

Background info

bcprov-jdk18on is vulnerable to Signature Verification Bypass in versions 1.85 - 1.85.2.

How to fix this

Upgrade the bcprov-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform