Description
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Severity (CVSS)
| Base score | 8.7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber |
| Provided by | CNA |
Weaknesses
- CWE-347 — CWE-347 Improper Verification of Cryptographic Signature
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc. | BC-JAVA | 0 to <1.85 |
| Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | 2.73.0 to <2.73.12 |
| Legion of the Bouncy Castle Inc. | BC-FJA | 1.0.0 to <1.0.12; 2.0.0 to <2.0.12; 2.1.0 to <2.1.12 |
References
Generated from the official CVE List on 03 Aug 2026 08:53 UTC.