CVE-2026-71887 - OpenPGP data signature accepted from a signing subkey without cross-certification
CVE ID :CVE-2026-71887 Published : Oct. 3, 2026, 8:39 a.m. | 45 minutes ago Description :In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding...