Impact
In Bouncy Castle Java before 1.86, the high‑level OpenPGP API accepts a data signature created with a signing subkey whose binding signature omits the required embedded Primary Key Binding cross‑certification when no Key Flags subpacket is present. The API incorrectly treats the subkey as signing‑capable, allowing the signature to be considered valid and attributed to the certificate, while the lack of cross‑certification means the binding was not verified. An attacker can exploit this by taking a victim’s publicly available signing subkey, binding it to their own primary key with a Subkey Binding signature that carries no Key Flags and no embedded Primary Key Binding, and then presenting that certificate to a verifier that uses the vulnerable API. The verifier will accept the signature as legitimate and report the attacker’s identity as the signer, resulting in misattribution of the signature without requiring possession of the private key. The vulnerability therefore undermines authenticity and trust in signed content, potentially facilitating impersonation and fraud.
Affected Systems
Any deployment of Bouncy Castle for Java with a library version older than 1.86 that relies on the high‑level OpenPGP API for signature verification is affected. This includes applications that use Bouncy Castle’s OpenPGPCertificate and OpenPGPSignature OpenPGPDocumentSignature classes. The low‑level PGPSignature and PGPPublicKeyRing APIs are not impacted.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity flaw. Because the exploit requires only the victim’s public signing subkey and can be carried out by crafting a Subkey Binding signature that omits required subpackets, the vulnerability is technically exploitable against any system that employs the vulnerable API. The EPSS score is not available, but the lack of coverage in the CISA KEV catalog does not diminish the intrinsic risk. An attacker’s ability to hijack a legitimate signature and misattribute it to a forged identity introduces a serious authenticity risk that can be leveraged for phishing, fraud, or denial of trust in software distributions.
OpenCVE Enrichment