Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3505

27
FAUCET Score

CVE-2026-3505 is an uncontrolled resource consumption vulnerability affecting the BC-JAVA cryptographic library from Legion of the Bouncy Castle Inc., specifically in the bcpg modules used for PGP operations. The flaw exists in versions 1.74 through 1.83 and stems from improper resource allocation without limits or throttling in files including AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, and OperatorHelper.Java. This type of vulnerability could allow attackers to exhaust system resources through maliciously crafted inputs. The vulnerability carries a FAUCET risk score of 42.0/100 and an EPSS score of 0.00055, indicating relatively low predicted exploitability compared to the broader CVE population. Without available CVSS scoring data, precise details regarding attack vector and complexity are unavailable; however, the nature of resource exhaustion vulnerabilities typically requires network access and moderate complexity. The impact would likely manifest as denial of service through CPU or memory exhaustion in systems using the affected library. There is currently no evidence of active exploitation, as indicated by the CVE's absence from the Known Exploited Vulnerabilities catalog and its inactive status on the Hot List. No public exploit code has been reported, and community attention remains minimal. Organizations using affected BC-JAVA versions should upgrade to 1.84 or later as a preventative measure.

Impacted Technologies

VendorProductVersion(s)CPE
Legion Of The Bouncy Castle Inc.BC-JAVA
>= 1.74, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.76%
Probability of exploitation in next 30 days
EPSS Percentile
51.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0076 is in the 27th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpg-jdk14Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpg-jdk15to18Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcpg-jdk18onFixed in: 1.84

Vendor Advisories (1)

mavenGHSA-cj8j-37rh-8475high

Bouncy Castle Uncontrolled Resource Consumption vulnerability

Apr 17, 2026

References

access.redhat.com / errata/RHSA-2026:13631
access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / security/cve/CVE-2026-3505
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-3505.json
github.com / bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1
github.com / bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%903505