Skip to main content
EPSS 0.2%top 96%

CVE-2026-85515: CWE-354 Improper Validation of Integrity Check Value in Legion of the Bouncy Castle Inc. BC-JAVA

0
High
VulnerabilityCVE-2026-85515cvecve-2026-85515cwe-354cwe-345
Published: 10/03/2026 (10/03/2026, 08:05:16 UTC)
Source: CVE Database V5
Vendor/Project: Legion of the Bouncy Castle Inc.
Product: BC-JAVA

Description

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an implementation to release the cleartext of the fully authenticated chunks when streaming but requires it to indicate a clear error as soon as the truncation is detected, and to report suspect integrity when it discovers malleable ciphertext. The truncation was detected and then discarded: when a message is truncated but the length field of the enclosing packet is left unchanged, BCPGInputStream.PartialInputStream raises an EOFException for the missing ciphertext, and BCPGInputStream.nextPacketTag() reports an EOFException as a clean end of message, so the packet stream above it stopped as though no packets remained. On the AEAD path (SEIPD version 2 and the version 5 AEAD packet), when the literal data packet ended on an AEAD chunk boundary and the consumer read in increments smaller than one chunk, the look-ahead for the packet after the literal triggered the truncated chunk read, so BcAEADUtil and JceAEADUtil never reached the trailing message tag of sec. 5.13.2 that authenticates the total plaintext length; the caller received the plaintext of the fully authenticated chunks, every packet following the literal was silently dropped, and no exception was raised, so a signed and encrypted message read back as a well-formed unsigned one. Every byte released on that path remained individually authenticated, making this a missing truncation error rather than a forgery, and it is a residual of CVE-2026-12817, which closed the same outcome for an attacker who corrects the outer packet length. On the SEIPD version 1 path the consequence was more serious: IntegrityProtectedInputStream verifies the modification detection code from close(), and reached close() only by closing itself when a read of it returned -1, which a truncated message never produces, so PGPEncryptedData.verify() never ran and the recipient was handed CFB-decrypted plaintext on which no integrity check of any kind had been performed. Measured on a message truncated into that shape, 136 distinct single-byte modifications of the ciphertext produced accepted, altered plaintext with no exception raised. Reachability is a property of the message rather than of attacker-supplied input: the AEAD shape held for 3 of 131 consecutive payload lengths measured, and the SEIPD version 1 shape for one payload length in sixteen, at a truncation offset that did not move with the payload length. The low-level API is unaffected, a caller that invokes PGPEncryptedData.verify() directly getting the check regardless, as are consumers reading in increments of a whole AEAD chunk or more. The AEAD decryption streams now re-throw such an EOFException as a plain IOException, which nextPacketTag() does not launder; OpenPGPMessageInputStream.close() now closes its layer's integrity-protected stream itself rather than relying on that stream having seen the end of its data; and IntegrityProtectedInputStream.close() was made idempotent, as java.io.Closeable requires, which that depends on, since the stream is genuinely closed twice on the ordinary path and PGPEncryptedData.verify() consumes the digest state behind it and cannot be run a second time. This issue also affects Bouncy Castle for Java LTS before 2.73.13, on the AEAD route only, as that edition does not ship the high-level OpenPGP API the SEIPDv1 route runs through. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.14 (1.0.X series), 2.0.14.1 (2.0.X series) and 2.1.14 (2.1.X series), on the AEAD route only, as those editions do not ship the high-level OpenPGP API.

CVSS v4.0

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber

Affected software

Legion of the Bouncy Castle Inc.

BC-JAVA

Affected versions
>=1.74 <1.86

Legion of the Bouncy Castle Inc.

BC-LTS-JAVA

Affected versions
>=2.73.0 <2.73.13

Legion of the Bouncy Castle Inc.

BC-FJA

Affected versions
>=1.0.7 <1.0.14>=2.0.7 <2.0.14.1>=2.1.0 <2.1.14
GitHub Actionsmore threats →cve
bcpg
pkg:github/bcpg
Affected versions
>=1.74 <1.86
GitHub Actionsmore threats →cve
bcpg-lts8on
pkg:github/bcpg-lts8on
Affected versions
>=2.73.0 <2.73.13

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 08:46:04 UTC

Technical Analysis

This vulnerability in Bouncy Castle for Java before 1.86 and certain later versions involves improper validation of integrity check values when processing truncated OpenPGP encrypted messages. On the SEIPD version 1 path, truncated messages bypass integrity checks entirely, allowing altered plaintext to be accepted without exception. On the AEAD path, truncated chunks can cause the trailing message tag that authenticates total plaintext length to be skipped, resulting in silent acceptance of partial plaintext and dropped packets. The low-level API is unaffected if PGPEncryptedData.verify() is called directly or if reading is done in increments of a full AEAD chunk or more. The vulnerability affects versions >=1.74 <1.86, >=2.73.0 <2.73.13, and certain FIPS versions before 1.0.14, 2.0.14.1, and 2.1.14. The issue was addressed by improving exception propagation, stream closure handling, and making IntegrityProtectedInputStream.close() idempotent.

Potential Impact

The vulnerability allows an attacker to cause truncated OpenPGP encrypted messages to be accepted without proper integrity verification, potentially resulting in altered plaintext being accepted silently. On the SEIPD version 1 path, this means no integrity check is performed, allowing 136 distinct single-byte ciphertext modifications to produce accepted altered plaintext without exceptions. On the AEAD path, partial plaintext from fully authenticated chunks may be released while subsequent packets are silently dropped, causing signed and encrypted messages to be read as unsigned. This undermines the cryptographic guarantees of message authenticity and integrity, posing a significant risk to confidentiality and trust in encrypted communications.

Mitigation Recommendations

A fix is available in Bouncy Castle for Java versions 1.86 and later, 2.73.13 and later, and FIPS editions bcpg-fips 1.0.14, 2.0.14.1, and 2.1.14 or later. Users should upgrade to these fixed versions to ensure proper integrity validation of OpenPGP encrypted messages. The vulnerability is mitigated by improved exception handling and stream closure behavior in these versions. No additional mitigation is required if using the low-level API correctly or reading in increments of full AEAD chunks. Patch status is confirmed by the vendor advisory. No known exploits in the wild have been reported.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
bcorg
Date Reserved
2026-09-04T05:38:18.070Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac0bd68a43b0b3b89ad2025

Added to database: 10/03/2026, 08:31:36 UTC

Last enriched: 10/03/2026, 08:46:04 UTC

Last updated: 10/04/2026, 05:45:56 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses