CVE-2026-3505 is an uncontrolled resource consumption vulnerability affecting the BC-JAVA cryptographic library from Legion of the Bouncy Castle Inc., specifically in the bcpg modules used for PGP operations. The flaw exists in versions 1.74 through 1.83 and stems from improper resource allocation without limits or throttling in files including AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, and OperatorHelper.Java. This type of vulnerability could allow attackers to exhaust system resources through maliciously crafted inputs. The vulnerability carries a FAUCET risk score of 42.0/100 and an EPSS score of 0.00055, indicating relatively low predicted exploitability compared to the broader CVE population. Without available CVSS scoring data, precise details regarding attack vector and complexity are unavailable; however, the nature of resource exhaustion vulnerabilities typically requires network access and moderate complexity. The impact would likely manifest as denial of service through CPU or memory exhaustion in systems using the affected library. There is currently no evidence of active exploitation, as indicated by the CVE's absence from the Known Exploited Vulnerabilities catalog and its inactive status on the Hot List. No public exploit code has been reported, and community attention remains minimal. Organizations using affected BC-JAVA versions should upgrade to 1.84 or later as a preventative measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Legion Of The Bouncy Castle Inc. | BC-JAVA | >= 1.74, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.