In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path… (CVE-2026-85515)
Bouncy Castle for Java versions before 1.86 contain a vulnerability where truncated OpenPGP encrypted messages are accepted without error, leading to missing integrity checks on certain decryption paths. Specifically, on the SEIPD version 1 path, truncated messages bypass integrity verification, allowing altered plaintext to be accepted silently. On the AEAD path, truncated chunks cause subsequent packets to be dropped without error, potentially causing signed and encrypted messages to be read as unsigned. This issue also affects certain LTS and FIPS editions on the AEAD route. The vulnerability is a missing truncation error rather than a forgery and is a residual effect of a previous CVE. The low-level API is unaffected, and reading in increments of a whole AEAD chunk or more avoids the issue. Fixes have been implemented in the handling of EOFExceptions and stream closing behavior.
AI Analysis
Technical Summary
In Bouncy Castle for Java prior to version 1.86, a truncated OpenPGP encrypted message could be accepted without reporting an error, violating RFC 9580 requirements for truncation detection and integrity checking. On the SEIPD version 1 path, the IntegrityProtectedInputStream never triggers the integrity verification on truncated messages, allowing altered plaintext to be accepted without exception. On the AEAD path (SEIPD version 2 and version 5 AEAD packets), truncated chunks cause the decryption utilities to drop subsequent packets silently, resulting in signed and encrypted messages being read as unsigned. The vulnerability is a missing truncation error rather than a forgery, and the low-level API remains unaffected. The issue also affects Bouncy Castle for Java LTS before 2.73.13 and Bouncy Castle for Java FIPS editions before specified versions on the AEAD route. The fix involves re-throwing EOFExceptions properly, ensuring streams close correctly, and making IntegrityProtectedInputStream.close() idempotent.
Potential Impact
The vulnerability allows truncated OpenPGP encrypted messages to be accepted without proper integrity verification, potentially resulting in altered plaintext being accepted silently on the SEIPD version 1 path. On the AEAD path, signed and encrypted messages may be read as unsigned due to silent dropping of packets after truncated chunks. This undermines the integrity guarantees of the encrypted messages. However, the low-level API and usage patterns that read in increments of whole AEAD chunks or more are not affected. The issue is a missing truncation error rather than a direct forgery, but it can lead to acceptance of modified plaintext without error.
Mitigation Recommendations
A fix is available in Bouncy Castle for Java version 1.86 and later, as well as in Bouncy Castle for Java LTS version 2.73.13 and Bouncy Castle for Java FIPS editions 1.0.14, 2.0.14.1, and 2.1.14 or later on the AEAD route. Users should upgrade to these fixed versions to ensure proper truncation detection and integrity verification. The low-level API users who invoke PGPEncryptedData.verify() directly are not affected. Reading in increments of whole AEAD chunks or more also avoids the issue. No additional mitigations are necessary once updated to the fixed versions.
In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path… (CVE-2026-85515)
Description
Bouncy Castle for Java versions before 1.86 contain a vulnerability where truncated OpenPGP encrypted messages are accepted without error, leading to missing integrity checks on certain decryption paths. Specifically, on the SEIPD version 1 path, truncated messages bypass integrity verification, allowing altered plaintext to be accepted silently. On the AEAD path, truncated chunks cause subsequent packets to be dropped without error, potentially causing signed and encrypted messages to be read as unsigned. This issue also affects certain LTS and FIPS editions on the AEAD route. The vulnerability is a missing truncation error rather than a forgery and is a residual effect of a previous CVE. The low-level API is unaffected, and reading in increments of a whole AEAD chunk or more avoids the issue. Fixes have been implemented in the handling of EOFExceptions and stream closing behavior.
CVSS v4.0
Affected software
pkg:maven/org.bouncycastle/bcprov-jdk15onRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Bouncy Castle for Java prior to version 1.86, a truncated OpenPGP encrypted message could be accepted without reporting an error, violating RFC 9580 requirements for truncation detection and integrity checking. On the SEIPD version 1 path, the IntegrityProtectedInputStream never triggers the integrity verification on truncated messages, allowing altered plaintext to be accepted without exception. On the AEAD path (SEIPD version 2 and version 5 AEAD packets), truncated chunks cause the decryption utilities to drop subsequent packets silently, resulting in signed and encrypted messages being read as unsigned. The vulnerability is a missing truncation error rather than a forgery, and the low-level API remains unaffected. The issue also affects Bouncy Castle for Java LTS before 2.73.13 and Bouncy Castle for Java FIPS editions before specified versions on the AEAD route. The fix involves re-throwing EOFExceptions properly, ensuring streams close correctly, and making IntegrityProtectedInputStream.close() idempotent.
Potential Impact
The vulnerability allows truncated OpenPGP encrypted messages to be accepted without proper integrity verification, potentially resulting in altered plaintext being accepted silently on the SEIPD version 1 path. On the AEAD path, signed and encrypted messages may be read as unsigned due to silent dropping of packets after truncated chunks. This undermines the integrity guarantees of the encrypted messages. However, the low-level API and usage patterns that read in increments of whole AEAD chunks or more are not affected. The issue is a missing truncation error rather than a direct forgery, but it can lead to acceptance of modified plaintext without error.
Mitigation Recommendations
A fix is available in Bouncy Castle for Java version 1.86 and later, as well as in Bouncy Castle for Java LTS version 2.73.13 and Bouncy Castle for Java FIPS editions 1.0.14, 2.0.14.1, and 2.1.14 or later on the AEAD route. Users should upgrade to these fixed versions to ensure proper truncation detection and integrity verification. The low-level API users who invoke PGPEncryptedData.verify() directly are not affected. Reading in increments of whole AEAD chunks or more also avoids the issue. No additional mitigations are necessary once updated to the fixed versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8hgf-w73g-3x6v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-85515"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac1397da43b0b3b89d66c8a
Added to database: 10/03/2026, 17:21:01 UTC
Last enriched: 10/03/2026, 17:30:37 UTC
Last updated: 10/04/2026, 02:46:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.