CVE-2026-3505
EUVD-2026-2285515.04.2026, 10:16
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).This issue affects BC-JAVA: before 1.84. Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.