PT-2026-33030 · Bouncy Castle · Bc-Java

·

CVE-2026-3505

·

Published

2026-04-15

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BC-JAVA versions prior to 1.84
Description An issue in the bcpg modules allows for unbounded PGP AEAD chunk size, which can lead to pre-authentication resource exhaustion. Resource exhaustion occurs when a system lacks limits or throttling on resource allocation, allowing a requester to consume all available system memory or CPU.
Recommendations Update to version 1.84 or later.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AV84730
CLEANSTART-2026-DY69070
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-KP10590
CLEANSTART-2026-MT41286
CLEANSTART-2026-RU36468
CLEANSTART-2026-SR31778
CLEANSTART-2026-TK07726
CLEANSTART-2026-VN28553
CLEANSTART-2026-WT54034
CVE-2026-3505
GHSA-CJ8J-37RH-8475
OPENSUSE-SU-2026:10571-1
OPENSUSE-SU-2026:20627-1
RHSA-2026:18054
RHSA-2026:18055
RHSA-2026:53644
SUSE-SU-2026:1639-1
SUSE-SU-2026:21404-1

Affected Products

Bc-Java