: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
This issue affects BC-JAVA: from 1.49 before 1.84.
{
"github_reviewed": true,
"nvd_published_at": "2026-04-15T10:16:49Z",
"cwe_ids": [
"CWE-327"
],
"github_reviewed_at": "2026-04-16T21:32:20Z",
"severity": "MODERATE"
}