Resource exhaustion in Bouncy Castle for Java - CVE-2026-3505

 

Resource exhaustion in Bouncy Castle for Java - CVE-2026-3505

Published: May 25, 2026


Vulnerability identifier: #VU132262
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3505
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the bcpg PGP AEAD processing when parsing crafted PGP data with an unbounded AEAD chunk size. A remote attacker can send specially crafted PGP data to cause a denial of service.

Exploitation leads to pre-authentication resource exhaustion.


Affected software

Bouncy Castle for Java
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Anolis OS
IBM SPSS Collaboration and Deployment Services
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
bouncycastle
bouncycastle-javadoc
bouncycastle-jmail
bouncycastle-mail
bouncycastle-pg
bouncycastle-pkix
bouncycastle-tls
bouncycastle-util

How to mitigate CVE-2026-3505

Install security update from vendor's website.

Bouncy Castle for Java - addressed in versions 1.80.2, 1.81.1, 1.84
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle - update to 1.84-1
bouncycastle-javadoc - update to 1.84-1
bouncycastle-jmail - update to 1.84-1
bouncycastle-mail - update to 1.84-1
bouncycastle-pg - update to 1.84-1
bouncycastle-pkix - update to 1.84-1
bouncycastle-tls - update to 1.84-1
bouncycastle-util - update to 1.84-1
bouncycastle - update to 1.84-150200.3.35.1
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
Red Hat Camel for Spring Boot - update to 4.14

External References

Related Security Bulletins