CVE-2026-71890 - MLS external commit can remove an arbitrary group member
CVE ID :CVE-2026-71890 Published : Oct. 3, 2026, 8:57 a.m. | 27 minutes ago Description :In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type...