10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).This issue affects BC-JAVA: before 1.84.
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
AI Analysis
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion in BC-JAVA before version 1.84.
Basic Information
ID
CVE-2026-3505
Source
bcorg
Published
Apr 15, 2026 at 09:06
Modified
Apr 15, 2026 at 10:33
Affected Product
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
Version
1.74
Affected Versions
Legion of the Bouncy Castle Inc. BC-JAVA 1.74
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
Version
before 1.84