CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This issue affects BC-JAVA before 1.84.
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
Other sources
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).This issue affects BC-JAVA: before 1.84.
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
— Red Hat
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).
This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
— MITRE
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java.
This issue affects BC-JAVA: from 1.74 before 1.84.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.bouncycastle:bcpg-jdk18onto a version that resolves this vulnerability.Fixed in 1.84 - Upgrade
Upgrade
maven/org.bouncycastle:bcpg-jdk15to18to a version that resolves this vulnerability.Fixed in 1.84 - Upgrade
Upgrade
maven/org.bouncycastle:bcpg-jdk14to a version that resolves this vulnerability.Fixed in 1.84
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3505?
CVE-2026-3505 is classified as a high severity vulnerability due to the potential for resource exhaustion attacks.
How do I fix CVE-2026-3505?
To fix CVE-2026-3505, upgrade Bouncy Castle BC-JAVA bcpg to version 1.84 or later.
What does CVE-2026-3505 impact?
CVE-2026-3505 impacts all versions of Bouncy Castle BC-JAVA bcpg prior to 1.84.
What type of vulnerability is CVE-2026-3505?
CVE-2026-3505 is an unbounded allocation vulnerability, leading to pre-authentication resource exhaustion.
Who is affected by CVE-2026-3505?
Any user or application utilizing Bouncy Castle BC-JAVA bcpg before version 1.84 is affected by CVE-2026-3505.