
CVE-2026-3505 Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This issue affects BC-JAVA before 1.84. Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
Post summary
The text announces CVE-2026-3505 as a resource exhaustion bug in Bouncy Castle BC-JAVA bcpg modules caused by unbounded PGP AEAD chunk size, affecting versions prior to 1.84.
