CVE-2026-71888 - CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent
CVE ID :CVE-2026-71888 Published : Oct. 3, 2026, 8:36 a.m. | 48 minutes ago Description :In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were...