Skip to main content
EPSS 0.2%top 96%

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path… (CVE-2026-85515)

0
High
Published: 10/03/2026 (10/03/2026, 09:31:18 UTC)
Source: GCVE Database

Description

Bouncy Castle for Java versions before 1.86 contain a vulnerability where truncated OpenPGP encrypted messages are accepted without error, leading to missing integrity checks on certain decryption paths. Specifically, on the SEIPD version 1 path, truncated messages bypass integrity verification, allowing altered plaintext to be accepted silently. On the AEAD path, truncated chunks cause subsequent packets to be dropped without error, potentially causing signed and encrypted messages to be read as unsigned. This issue also affects certain LTS and FIPS editions on the AEAD route. The vulnerability is a missing truncation error rather than a forgery and is a residual effect of a previous CVE. The low-level API is unaffected, and reading in increments of a whole AEAD chunk or more avoids the issue. Fixes have been implemented in the handling of EOFExceptions and stream closing behavior.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
Scope
X
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

Affected software

org.bouncycastle/bcprov-jdk15on
pkg:maven/org.bouncycastle/bcprov-jdk15on
Affected versions
<1.86

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:30:37 UTC

Technical Analysis

In Bouncy Castle for Java prior to version 1.86, a truncated OpenPGP encrypted message could be accepted without reporting an error, violating RFC 9580 requirements for truncation detection and integrity checking. On the SEIPD version 1 path, the IntegrityProtectedInputStream never triggers the integrity verification on truncated messages, allowing altered plaintext to be accepted without exception. On the AEAD path (SEIPD version 2 and version 5 AEAD packets), truncated chunks cause the decryption utilities to drop subsequent packets silently, resulting in signed and encrypted messages being read as unsigned. The vulnerability is a missing truncation error rather than a forgery, and the low-level API remains unaffected. The issue also affects Bouncy Castle for Java LTS before 2.73.13 and Bouncy Castle for Java FIPS editions before specified versions on the AEAD route. The fix involves re-throwing EOFExceptions properly, ensuring streams close correctly, and making IntegrityProtectedInputStream.close() idempotent.

Potential Impact

The vulnerability allows truncated OpenPGP encrypted messages to be accepted without proper integrity verification, potentially resulting in altered plaintext being accepted silently on the SEIPD version 1 path. On the AEAD path, signed and encrypted messages may be read as unsigned due to silent dropping of packets after truncated chunks. This undermines the integrity guarantees of the encrypted messages. However, the low-level API and usage patterns that read in increments of whole AEAD chunks or more are not affected. The issue is a missing truncation error rather than a direct forgery, but it can lead to acceptance of modified plaintext without error.

Mitigation Recommendations

A fix is available in Bouncy Castle for Java version 1.86 and later, as well as in Bouncy Castle for Java LTS version 2.73.13 and Bouncy Castle for Java FIPS editions 1.0.14, 2.0.14.1, and 2.1.14 or later on the AEAD route. Users should upgrade to these fixed versions to ensure proper truncation detection and integrity verification. The low-level API users who invoke PGPEncryptedData.verify() directly are not affected. Reading in increments of whole AEAD chunks or more also avoids the issue. No additional mitigations are necessary once updated to the fixed versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8hgf-w73g-3x6v
Osv Schema Version
1.4.0
Aliases
["CVE-2026-85515"]
Database Specific Severity
HIGH
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac1397da43b0b3b89d66c8a

Added to database: 10/03/2026, 17:21:01 UTC

Last enriched: 10/03/2026, 17:30:37 UTC

Last updated: 10/04/2026, 02:46:07 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses