CVE-2026-3505
published 2026-04-15CVE-2026-3505: Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.79%
53.8th percentile
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).
This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| candlepinproject | candlepin | — | — |
| jenkins | jenkins | — | — |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.74 < 1.80.2 | 1.80.2 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.81 < 1.81.1 | 1.81.1 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.82 < 1.84 | 1.84 |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion
vendor_redhat·2026-04-15·CVSS 8.7
CVE-2026-3505 [HIGH] CWE-770 bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion
bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java.
This issue affects BC-JAVA: from 1.74 before 1.84.
A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA bcpg. A specially crafted PGP AEAD (Authenticated Encryption with Associated Data) message with an unbounded chunk size can lead to an excessive consumption of memory. This issue allows an unauthenticated remote attacker to cause memory exhaustion in a JVM, resulting in a denial of service.
GHSA
Bouncy Castle Uncontrolled Resource Consumption vulnerability
ghsa·2026-04-17
CVE-2026-3505 [HIGH] CWE-400 Bouncy Castle Uncontrolled Resource Consumption vulnerability
Bouncy Castle Uncontrolled Resource Consumption vulnerability
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This issue affects BC-JAVA before 1.84.
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
VulDB
Legion of the Bouncy Castle BC-JAVA up to 1.83 allocation of resources
vuldb·2026-04-15·CVSS 8.7
CVE-2026-3505 [HIGH] Legion of the Bouncy Castle BC-JAVA up to 1.83 allocation of resources
A vulnerability has been found in Legion of the Bouncy Castle BC-JAVA up to 1.83 and classified as critical. This affects an unknown part. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-3505. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%903505https://access.redhat.com/errata/RHSA-2026:13631https://access.redhat.com/errata/RHSA-2026:17668https://access.redhat.com/errata/RHSA-2026:18054https://access.redhat.com/errata/RHSA-2026:18055https://access.redhat.com/errata/RHSA-2026:18059https://access.redhat.com/errata/RHSA-2026:53644https://access.redhat.com/errata/RHSA-2026:53806https://access.redhat.com/errata/RHSA-2026:60239https://access.redhat.com/errata/RHSA-2026:60246https://access.redhat.com/errata/RHSA-2026:60247https://access.redhat.com/errata/RHSA-2026:60248https://access.redhat.com/errata/RHSA-2026:60249https://access.redhat.com/errata/RHSA-2026:60250https://access.redhat.com/errata/RHSA-2026:60251https://access.redhat.com/errata/RHSA-2026:60252https://access.redhat.com/errata/RHSA-2026:60254https://access.redhat.com/errata/RHSA-2026:60256https://access.redhat.com/errata/RHSA-2026:60259https://access.redhat.com/security/cve/CVE-2026-3505https://bugzilla.redhat.com/show_bug.cgi?id=2458638https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3505.json
2026-04-15
Published