天下漏洞,尽知其名
MEDIUM

CVE-2026-71889 Bouncy Castle 证书路径校验绕过漏洞

影响攻击者可绕过名称约束,使受限 CA 签发的非法证书被判定为有效

MEDIUM
暂无 CVSS 评分
AI 研判

Bouncy Castle for Java 1.86 之前的 PKIXCertPathReviewer(jcajce 与 legacy x509 两个副本)在检查 X.509 名称约束时,循环从索引 1 开始,未对路径中索引 0 的终端实体证书执行 RFC 5280 6.1.3 (b)(c) 的 permitted/excluded 子树检查。因此当叶子证书违反其签发 CA 施加的 NameConstraints 时,isValidCertPath() 仍返回 true 且错误列表为空,而共享不同代码的 CertPathValidator PKIX 实现会正确拒绝同一证书链。

影响范围

Bouncy Castle

Bouncy Castle for Java 1.86 之前的版本,涉及 org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer 与 org.bouncycastle.x509.PKIXCertPathReviewer 两个类。

漏洞详情

漏洞类型为证书路径校验绕过(名称约束未生效)。成因是 checkNameConstraints 的循环边界设为 index > 0,遗漏了标准 CertPath 顺序中位于索引 0 的目标证书,导致 RFC 5280 规定的 permitted 与 excluded 子树检查从未作用于叶子证书的 subject DN 和 subjectAltName。利用方式是构造一条叶子证书违反其签发 CA NameConstraints 的证书链,使依赖该 reviewer 做信任决策的应用误判为有效。

利用条件与风险

利用前提是应用直接使用 PKIXCertPathReviewer 的校验结果作为信任决策依据,而非仅作诊断;实战中可导致受限 CA 越权签发的证书被接受,造成身份伪造或中间人风险。

修复建议

升级至 Bouncy Castle for Java 1.86 或更高版本,该版本已对路径中包括目标证书在内的每个证书执行检查;临时缓解措施为改用 CertPathValidator.getInstance("PKIX", "BC") 进行实际校验,不单独依赖 reviewer 的结论。

原始情报

In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer – org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer – applied X.509 name constraints to the end-entity certificate. checkNameConstraints walked the path with a loop bound of index greater than zero, which is the bound the CA-only steps require, but index zero is the target certificate under the standard CertPath ordering, so the permitted and excluded subtree checks of RFC 5280 sec. 6.1.3 (b) and (c) never ran against the leaf’s subject DN or its subjectAltName. A chain whose leaf violated a NameConstraints extension imposed by its own issuing CA therefore reported isValidCertPath() true with an empty error list, while CertPathValidator.getInstance(“PKIX”, “BC”), which shares no code with the reviewer, rejected the identical chain against the identical trust anchor. An application using the reviewer to make the trust decision rather than for diagnostics alongside a real validation accepted a certificate the constrained CA was never authorised to issue. Both copies now check every certificate in the path including the target, waive the sec. 4.2.1.10 self-issued exemption for the final certificate as sec. 6.1.3 requires, and skip the sec. 6.1.4 (g) constraint-accumulation step for the target. This issue also affects Bouncy Castle for Java LTS before 2.73.13, which carries only the org.bouncycastle.pkix.jcajce copy of the reviewer. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).