bcpg-jdk18on is vulnerable to Improper Validation of Integrity Check Value
87
High Risk
Bouncy Castle's OpenPGP AEAD decryption omits verification of the final authentication tag when the ciphertext ends on a chunk boundary. A tampered message can have its trailing plaintext chunk silently stripped or altered and still be accepted as authentic. This breaks the AEAD integrity guarantee and can also expose message contents. The fix verifies the final tag unconditionally before signalling end of stream in both the Bc and Jce decryptors.
You are affected if you are using a version that falls within the vulnerable range and your application performs OpenPGP AEAD (SEIPDv2/v5) decryption on externally supplied messages.
bcpg-jdk18on is vulnerable to Improper Validation of Integrity Check Value in versions 1.74.0 - 1.84.0.
Upgrade the org.bouncycastle:bcpg-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant