Intel

AIKIDO-2026-292457

bcpg-jdk18on is vulnerable to Integrity Check Bypass

Integrity Check BypassCVE-2026-85515 Published Yesterday

82

High Risk

This Affects:

JAVAbcpg-jdk18on
1.74 - 1.85
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

OpenPGP decryption treats truncation as a clean end of input and releases partial plaintext without reporting a failed or missing integrity check. The fix stops an AEAD end-of-file from being treated as success and closes the high-level integrity stream so SEIPDv1 MDC verification cannot be skipped.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you decrypt attacker-truncated OpenPGP AEAD messages or use the high-level API for integrity-protected SEIPDv1 messages.

Background info

bcpg-jdk18on is vulnerable to Integrity Check Bypass in versions 1.74 - 1.85.

How to fix this

Upgrade the bcpg-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform