OpenPGP Vulnerability in Bouncy Castle for Java Affecting Key Integrity and Data Security
CVE-2026-85515

8.2HIGH

What is CVE-2026-85515?

A vulnerability in Bouncy Castle for Java allows the acceptance of truncated OpenPGP encrypted messages without any errors, posing significant risks to data integrity. Specifically, when truncated messages are processed, they can be misleadingly treated as valid, resulting in serious security ramifications. An attacker could exploit this flaw to deliver altered plaintext while bypassing integrity checks, potentially leading to unauthorized data manipulation. This vulnerability spans several versions, affecting both standard and FIPS-compliant editions of Bouncy Castle, under specific pathways that undermine expected encryption protections. The necessity for developers to update to the latest versions is paramount to mitigate associated risks.

Affected Version(s)

BC-FJA all 1.0.7 < 1.0.14

BC-FJA all 2.0.7 < 2.0.14.1

BC-FJA all 2.1.0 < 2.1.14

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arpan Sharma
.