CVE-2026-71888 Bouncy Castle Java CMS AuthenticatedData 解析不一致漏洞
影响攻击者可篡改消息并注入未认证属性,误导授权或路由决策
Bouncy Castle for Java 1.86 之前的流式 CMS AuthenticatedData 解析器在处理 digestAlgorithm 与 authAttrs 字段不一致的消息时存在逻辑缺陷。当消息缺少 digestAlgorithm 但包含 authAttrs 时,解析器仅依据 digestAlgorithm 判断是否认证属性,导致 MAC 未覆盖的 authAttrs 被当作已认证属性返回。攻击者可在传输中向合法消息插入伪造的认证属性。
影响范围
Bouncy Castle for Java 1.86 之前的版本,具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于解析不一致(认证绕过)问题。RFC 5652 要求 digestAlgorithm 与 authAttrs 成对出现,且 MAC 覆盖范围取决于 authAttrs 是否存在。CMSAuthenticatedDataParser 在构造函数中因 authAttrs 位于 SEQUENCE 后部而只能先依据 digestAlgorithm 做选择,导致 digestAlgorithm 缺失但 authAttrs 存在时,属性未经 MAC 保护即被 getAuthAttrs() 返回。攻击者无需持有密钥加密密钥或内容 MAC 密钥即可插入如 ESSSecurityLabel 等属性。
利用条件与风险
利用前提是攻击者能修改传输中的 CMS 消息,且应用依据这些属性做授权、路由或标签决策。实战中可导致权限提升或错误的安全标签判定,风险中等。
修复建议
升级至 Bouncy Castle for Java 1.86 或更高版本。临时缓解措施暂无公开信息,建议对来自不可信来源的 CMS AuthenticatedData 消息加强校验,不单独依赖 authAttrs 做安全决策。
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2 makes the MAC cover the DER encoding of authAttrs when they are present and the eContent OCTET STRING directly when they are not. CMSAuthenticatedDataParser has to choose between those two in its constructor, before it can reach authAttrs, which comes later in the SEQUENCE, so it chose on digestAlgorithm alone: for a message with digestAlgorithm absent but authAttrs present it verified the content MAC and then returned the attributes through getAuthAttrs() as though they had been authenticated, when the MAC had never covered them. An attacker able to modify a message in transit could insert an authenticated attribute, such as an RFC 2634 ESSSecurityLabel, into an otherwise valid message while holding neither the key-encryption key nor the content-MAC key, and an application taking an authorization, routing or labelling decision from those attributes would act on attacker-chosen values. The content itself remained MAC-bound. asn1.cms.AuthenticatedData now rejects the mismatched pairing when parsing and CMSAuthenticatedDataParser cross-checks the two fields once authAttrs is read. This is a variant of CVE-2026-59642, which bound the content to the MAC for messages that legitimately carry authAttrs, and which does not address this case. This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), and bcutil-fips 2.0.8 (2.0.X series) and 2.1.8 (2.1.X series).