Bug 2510253 (CVE-2026-12817)

Summary: CVE-2026-12817 bouncycastle: Bouncy Castle for Java: Integrity bypass in OpenPGP AEAD decryption
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anujha, asoldano, bbaranow, bmaxwell, bstansbe, dlofthou, gmalinko, istudens, ivassile, iweiss, janstey, mosmerov, msvehla, nwallace, pberan, pdelbell, pesilva, pjindal, pmackay, rstancel, rstepani, thjenkin, vdosoudi
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Bouncy Castle for Java. This vulnerability affects the OpenPGP Authenticated Encryption with Associated Data (AEAD) decryption process. Specifically, the system fails to verify the final authentication tag when processing data that is aligned in chunks. This oversight could allow a remote attacker to modify encrypted information without being detected, leading to a compromise of data integrity.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2524916, 2524921    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-03 04:01:16 UTC
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).