Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).
This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
{
"cna_assigner": "bcorg",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3505.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.74"
},
{
"fixed": "1.80.2"
},
{
"introduced": "1.81"
},
{
"fixed": "1.81.1"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-400",
"CWE-770"
]
}"2026-07-22T03:57:14Z"
[
{
"target": {
"function": "AEADEncDataPacket",
"file": "pg/src/main/java/org/bouncycastle/bcpg/AEADEncDataPacket.java"
},
"id": "CVE-2026-3505-259964fb",
"digest": {
"function_hash": "133693706121194596895599095782657930270",
"length": 276.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"file": "pg/src/main/java/org/bouncycastle/openpgp/operator/jcajce/JceAEADUtil.java"
},
"id": "CVE-2026-3505-39566f4c",
"digest": {
"line_hashes": [
"71025605491745602052924149608823274766",
"310731032045546833422769943377507655128",
"160549492033834717715730648205076706458",
"76646762692607757591284513999651407526",
"149636761001252918748710122860092448471",
"32295880723942071177693895335431943063",
"284202989493960541444813002470377791376",
"285583721303767192109140908784123218090",
"12993474877920469471490353429867255940",
"155095222273678534637346255089161867984",
"171018653604802339835613152519986951644",
"264116330761582184852524645785897835646",
"112913710990562359606034788938886814024",
"211779906906995998069344729180269906205",
"201510249762378259754640110403805602238",
"281245874084301066187141488781262943300",
"168135225115955492698625883894381153075",
"62971514908783170117114022263834442041",
"207917066479958795962309976311552607358",
"196006495267980726221879766672465919674",
"284817506535797265382397512151913464593",
"59032994542508126003994475560421617017",
"77746061247247822461187162513723974896",
"121924566491907419028988670641367881437",
"296735144063196217551424621363002671310",
"238388167389063509072341480212088912608",
"295530012251069178443796808079503490494",
"248214079537556908678550127825736721269",
"195021759748862588758426888974152775799",
"271434759221742466965833086985591764699",
"9228363680992418995149615503969894328",
"293129950083765559252828737923948809376",
"108977944387750713206661158422406266181"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"file": "pg/src/main/java/org/bouncycastle/openpgp/operator/bc/BcAEADUtil.java"
},
"id": "CVE-2026-3505-4b8bbfe1",
"digest": {
"line_hashes": [
"285878165545623495223851167745664300155",
"192234171471621147435281040186000092603",
"301244109404689292528133019141818652760",
"7414647497590512723801598259511551204",
"338186994963320005695478244754396895291",
"326741319498582228717243590041233865706",
"142923806588497415763086745671957036662",
"24636163207322770183512867557744037940",
"188402880640059597683404690276529694278",
"79702742069006965803341552656161051704",
"185127959471245295373824817193819438770",
"145177505563016586211471918385529444634",
"264116330761582184852524645785897835646",
"112913710990562359606034788938886814024",
"211779906906995998069344729180269906205",
"201510249762378259754640110403805602238",
"281245874084301066187141488781262943300",
"168135225115955492698625883894381153075",
"62971514908783170117114022263834442041",
"207917066479958795962309976311552607358",
"196006495267980726221879766672465919674",
"284817506535797265382397512151913464593",
"59032994542508126003994475560421617017",
"77746061247247822461187162513723974896",
"121924566491907419028988670641367881437",
"296735144063196217551424621363002671310",
"238388167389063509072341480212088912608",
"295530012251069178443796808079503490494",
"248214079537556908678550127825736721269",
"195021759748862588758426888974152775799",
"271434759221742466965833086985591764699",
"9228363680992418995149615503969894328",
"190393985411334108831192613698705040211",
"110148957855410398885835607461921433728"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"function": "getChunkLength",
"file": "pg/src/main/java/org/bouncycastle/openpgp/operator/jcajce/JceAEADUtil.java"
},
"id": "CVE-2026-3505-52eb9d85",
"digest": {
"function_hash": "127480484942166568802898486158658595577",
"length": 64.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"function": "getChunkLength",
"file": "pg/src/main/java/org/bouncycastle/openpgp/operator/bc/BcAEADUtil.java"
},
"id": "CVE-2026-3505-66ea05f1",
"digest": {
"function_hash": "127480484942166568802898486158658595577",
"length": 64.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"file": "pg/src/test/java/org/bouncycastle/bcpg/test/OCBEncryptedDataPacketTest.java"
},
"id": "CVE-2026-3505-6ccbb530",
"digest": {
"line_hashes": [
"148210340888429101470727309296676997075",
"192846637382936663107583765695032048487",
"271685302753134285403068799461670674482",
"192338502122362787415574499601625781631",
"335624799150062828030668930698554109557",
"200602150673875433738633184510882274870",
"3860009734607546062795687315895873498"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"file": "pg/src/main/java/org/bouncycastle/bcpg/AEADEncDataPacket.java"
},
"id": "CVE-2026-3505-700a3b8d",
"digest": {
"line_hashes": [
"33204885417667225567725244573004281072",
"71298720310949047496891476662416475978",
"60443664955333907887634474099051352093",
"309813116599416355038273509040951481668",
"216400035679873215826861458934911832854",
"227122649040224449317036488890823539271"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"file": "pg/src/main/jdk1.4/org/bouncycastle/openpgp/operator/jcajce/OperatorHelper.java"
},
"id": "CVE-2026-3505-76048b20",
"digest": {
"line_hashes": [
"189952258396038691898146836242297926520",
"97542714641064228771552896973302933668",
"246916730924191021857668940983491349952",
"230016528334145973967505432988914856429"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"function": "performTest",
"file": "pg/src/test/java/org/bouncycastle/bcpg/test/OCBEncryptedDataPacketTest.java"
},
"id": "CVE-2026-3505-7dfc810f",
"digest": {
"function_hash": "326378283226324396674507459100442546863",
"length": 69.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"function": "AEADEncDataPacket",
"file": "pg/src/main/java/org/bouncycastle/bcpg/AEADEncDataPacket.java"
},
"id": "CVE-2026-3505-9ca261ea",
"digest": {
"function_hash": "102784975347065144442967767459576080182",
"length": 612.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
},
{
"target": {
"function": "getChunkLength",
"file": "pg/src/main/jdk1.4/org/bouncycastle/openpgp/operator/jcajce/OperatorHelper.java"
},
"id": "CVE-2026-3505-ddc7c9f6",
"digest": {
"function_hash": "127480484942166568802898486158658595577",
"length": 64.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/bcgit/bc-java/commit/dc7530939ffb6cdb57636f3609d98e23b94e71c1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3505.json"