CVE-2026-85515 | Legion of the Bouncy Castle Bouncy Castle for Java up to bcpg-fips 2.1.13 High-Level OpenPGP API PGPEncryptedData.verify integrity check
A vulnerability labeled as critical has been found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS up to 1.85.99/2.73.12/bcpg-fips 1.0.13/bcpg-fips 2.0.14.0/bcpg-fips 2.1.13. The impacted element is the function PGPEncryptedData.verify of the component High-Level OpenPGP API. Executing a manipulation can lead to improper validation of integrity check value.
This vulnerability is tracked as CVE-2026-85515. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More