Resource exhaustion in The Bouncy Castle Crypto Package For Java - CVE-2026-3505
Published: May 25, 2026
The Bouncy Castle Crypto Package For Java
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the bcpg PGP AEAD processing when parsing crafted PGP data with an unbounded AEAD chunk size. A remote attacker can send specially crafted PGP data to cause a denial of service.
Exploitation leads to pre-authentication resource exhaustion.