Impact
In Bouncy Castle for Java before version 1.86 a truncated OpenPGP encrypted message was accepted without reporting an error. The flaw is a missing verification weakness (CWE‑345) and improper handling of truncation (CWE‑354). On the SEIPDv1 path the integrity check was omitted entirely, and on the AEAD path the final authentication tag was never processed if the message ended on a chunk boundary, allowing silently dropped packets and treating signed messages as unsigned. The result is that an attacker can release tampered plaintext or cause confidential data to be discarded while no exception is raised, effectively bypassing the expected integrity guarantees.
Affected Systems
This flaw affects Bouncy Castle for Java before 1.86, Bouncy Castle for Java LTS before 2.73.13 (AEAD route only), and Bouncy Castle for Java FIPS (BC‑FJA) before bcpg‑fips 1.0.14, 2.0.14.1 or 2.1.14 (AEAD route only). All affected builds use the OpenPGP high‑level API and do not provide the updated truncation handling present in later releases.
Risk and Exploitability
The CVSS score is 8.2 and EPSS data is not available; the vulnerability is not listed in the CISA KEV catalog. It can be exploited by any application that processes untrusted PGP messages with an affected version of the library, either locally or remotely, simply by delivering a crafted truncated packet. The lack of an error response makes detection hard and the impact scope is the full message contents processed by the vulnerable path.
OpenCVE Enrichment