CVE-2026-85515
Received Received - Intake

Truncated OpenPGP Message Accepted Without Integrity Check in Bouncy Castle for Java

Vulnerability report for CVE-2026-85515, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an implementation to release the cleartext of the fully authenticated chunks when streaming but requires it to indicate a clear error as soon as the truncation is detected, and to report suspect integrity when it discovers malleable ciphertext. The truncation was detected and then discarded: when a message is truncated but the length field of the enclosing packet is left unchanged, BCPGInputStream.PartialInputStream raises an EOFException for the missing ciphertext, and BCPGInputStream.nextPacketTag() reports an EOFException as a clean end of message, so the packet stream above it stopped as though no packets remained. On the AEAD path (SEIPD version 2 and the version 5 AEAD packet), when the literal data packet ended on an AEAD chunk boundary and the consumer read in increments smaller than one chunk, the look-ahead for the packet after the literal triggered the truncated chunk read, so BcAEADUtil and JceAEADUtil never reached the trailing message tag of sec. 5.13.2 that authenticates the total plaintext length; the caller received the plaintext of the fully authenticated chunks, every packet following the literal was silently dropped, and no exception was raised, so a signed and encrypted message read back as a well-formed unsigned one. Every byte released on that path remained individually authenticated, making this a missing truncation error rather than a forgery, and it is a residual of CVE-2026-12817, which closed the same outcome for an attacker who corrects the outer packet length. On the SEIPD version 1 path the consequence was more serious: IntegrityProtectedInputStream verifies the modification detection code from close(), and reached close() only by closing itself when a read of it returned -1, which a truncated message never produces, so PGPEncryptedData.verify() never ran and the recipient was handed CFB-decrypted plaintext on which no integrity check of any kind had been performed. Measured on a message truncated into that shape, 136 distinct single-byte modifications of the ciphertext produced accepted, altered plaintext with no exception raised. Reachability is a property of the message rather than of attacker-supplied input: the AEAD shape held for 3 of 131 consecutive payload lengths measured, and the SEIPD version 1 shape for one payload length in sixteen, at a truncation offset that did not move with the payload length. The low-level API is unaffected, a caller that invokes PGPEncryptedData.verify() directly getting the check regardless, as are consumers reading in increments of a whole AEAD chunk or more. The AEAD decryption streams now re-throw such an EOFException as a plain IOException, which nextPacketTag() does not launder; OpenPGPMessageInputStream.close() now closes its layer's integrity-protected stream itself rather than relying on that stream having seen the end of its data; and IntegrityProtectedInputStream.close() was made idempotent, as java.io.Closeable requires, which that depends on, since the stream is genuinely closed twice on the ordinary path and PGPEncryptedData.verify() consumes the digest state behind it and cannot be run a second time. This issue also affects Bouncy Castle for Java LTS before 2.73.13, on the AEAD route only, as that edition does not ship the high-level OpenPGP API the SEIPDv1 route runs through. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.14 (1.0.X series), 2.0.14.1 (2.0.X series) and 2.1.14 (2.1.X series), on the AEAD route only, as those editions do not ship the high-level OpenPGP API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
bouncy_castle bc 1.86
bouncy_castle bc_lts 2.73.13
bouncy_castle bc_fja bcpg-fips_1.0.14
bouncy_castle bc_fja bcpg-fips_2.0.14.1
bouncy_castle bc_fja bcpg-fips_2.1.14
bouncy_castle bouncy_castle to 1.86 (exc)
bouncy_castle bouncy_castle_lts to 2.73.13 (exc)
bouncy_castle bouncy_castle_fips to 2.1.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85515 is a vulnerability in Bouncy Castle's Java library affecting OpenPGP message processing before specific versions. It involves truncated OpenPGP encrypted messages being accepted without error, bypassing integrity checks. The issue occurs in two paths: AEAD (SEIPDv2 and v5) and SEIPDv1 (MDC). In AEAD, truncated chunks are silently dropped, returning plaintext without error. In SEIPDv1, the modification detection code is never verified, allowing altered plaintext to be accepted.

Detection Guidance

Detecting this vulnerability requires checking the version of Bouncy Castle's Java library in use. Commands include: for Maven projects, check the dependency version in pom.xml; for Gradle, inspect build.gradle; and for direct JAR files, use 'java -jar your-jar.jar' or 'jar tf your-jar.jar | grep bcpg' to identify the version. Ensure versions are not below 1.86 for BC, 2.73.13 for BC-LTS, or the specified bcpg-fips versions.

Impact Analysis

This vulnerability allows attackers to modify encrypted messages without detection, potentially altering plaintext content. In SEIPDv1, it completely bypasses integrity checks, releasing unauthenticated plaintext. In AEAD, it silently drops packets, returning incomplete or altered data. Attackers can exploit this to forge or tamper with sensitive information in PGP-encrypted communications.

Compliance Impact

This vulnerability compromises data integrity and confidentiality, violating GDPR's principles of integrity and confidentiality (Article 5) and HIPAA's security requirements for protecting electronic protected health information. Non-compliance risks include legal penalties, loss of trust, and potential data breaches due to undetected message tampering.

Mitigation Strategies

Immediately upgrade Bouncy Castle libraries to patched versions: BC to 1.86 or later, BC-LTS to 2.73.13 or later, and BC-FJA to the specified bcpg-fips versions. Review OpenPGP message processing code to ensure integrity checks are enforced, particularly for SEIPDv1 and AEAD routes. Monitor for anomalous plaintext outputs or missing integrity errors in decrypted messages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85515. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart