Resource exhaustion in Bouncy Castle for Java - CVE-2026-3505
Published: May 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the bcpg PGP AEAD processing when parsing crafted PGP data with an unbounded AEAD chunk size. A remote attacker can send specially crafted PGP data to cause a denial of service.
Exploitation leads to pre-authentication resource exhaustion.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Anolis OS
IBM SPSS Collaboration and Deployment Services
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
bouncycastle
bouncycastle-javadoc
bouncycastle-jmail
bouncycastle-mail
bouncycastle-pg
bouncycastle-pkix
bouncycastle-tls
bouncycastle-util
How to mitigate CVE-2026-3505
IBM App Connect Enterprise - update to 13.0.8.0
bouncycastle - update to 1.84-1
bouncycastle-javadoc - update to 1.84-1
bouncycastle-jmail - update to 1.84-1
bouncycastle-mail - update to 1.84-1
bouncycastle-pg - update to 1.84-1
bouncycastle-pkix - update to 1.84-1
bouncycastle-tls - update to 1.84-1
bouncycastle-util - update to 1.84-1
bouncycastle - update to 1.84-150200.3.35.1
bouncycastle-pkix - update to 1.84-150200.3.35.1
bouncycastle-util - update to 1.84-150200.3.35.1
bouncycastle-pg - update to 1.84-150200.3.35.1
Red Hat Camel for Spring Boot - update to 4.14
External References
Related Security Bulletins
- Multiple vulnerabilities in Bouncy Castle for Java
- Anolis OS update for bouncycastle
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- SUSE update for bouncycastle
- IBM SPSS Collaboration and Deployment Services update forLegion of the Bouncy Castle Inc
- Multiple vulnerabilities in IBM App Connect Enterprise