CVE-2026-3505 HIGH

CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.

Vendor Legion Of The Bouncy Castle Inc.
Product BC-JAVA
Weakness CWE-770 · Uncontrolled resource consumption
Published April 15, 2026
Last update June 30, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

Key dates

02Disclosure timeline

April 15, 2026 CVE published
June 30, 2026 Record updated