Description

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

Severity (CVSS)

Base score8.7
SeverityHigh
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Provided byCNA

Weaknesses

  • CWE-347 — CWE-347 Improper Verification of Cryptographic Signature

Affected products

VendorProductVersions
Legion of the Bouncy Castle Inc.BC-JAVA0 to <1.85
Legion of the Bouncy Castle Inc.BC-LTS-JAVA2.73.0 to <2.73.12
Legion of the Bouncy Castle Inc.BC-FJA1.0.0 to <1.0.12; 2.0.0 to <2.0.12; 2.1.0 to <2.1.12

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 03 Aug 2026 08:53 UTC.