OpenPGP Vulnerability in Bouncy Castle for Java Affecting Key Integrity and Data Security
CVE-2026-85515
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-85515?
A vulnerability in Bouncy Castle for Java allows the acceptance of truncated OpenPGP encrypted messages without any errors, posing significant risks to data integrity. Specifically, when truncated messages are processed, they can be misleadingly treated as valid, resulting in serious security ramifications. An attacker could exploit this flaw to deliver altered plaintext while bypassing integrity checks, potentially leading to unauthorized data manipulation. This vulnerability spans several versions, affecting both standard and FIPS-compliant editions of Bouncy Castle, under specific pathways that undermine expected encryption protections. The necessity for developers to update to the latest versions is paramount to mitigate associated risks.
Affected Version(s)
BC-FJA all 1.0.7 < 1.0.14
BC-FJA all 2.0.7 < 2.0.14.1
BC-FJA all 2.1.0 < 2.1.14
