CVE-2026-71886 - OpenPGP certification accepted from a subkey without certification authority
CVE ID :CVE-2026-71886 Published : Oct. 3, 2026, 8:46 a.m. | 37 minutes ago Description :In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring...