bcpg-jdk18on is vulnerable to Observable Discrepancy
87
High Risk
Bouncy Castle's OpenPGP decryption keeps the legacy CFB quick-check bytes active on the symmetric-key and session-key paths. Because a quick-check mismatch is observable, the routine behaves as a decryption oracle that leaks information about the underlying key or plaintext. Repeated queries let confidential key material and message content be recovered. The fix removes the exploitable quick-check oracle on those paths.
You are affected if you are using a version that falls within the vulnerable range and your application decrypts OpenPGP messages that use the symmetric-key or session-key CFB (non-AEAD) path with externally supplied input.
bcpg-jdk18on is vulnerable to Observable Discrepancy in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpg-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant