CVE-2026-3505 Unknown

CVE-2026-3505

SUSE Released: April 17, 2026 Updated: April 18, 2026 Restart Required

Description

CVE-2026-3505 Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).This issue affects BC-JAVA: before 1.84. Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).

Fixed Vulnerabilities 1

CVE-2026-3505 N/A 0.0 ⚠️ KEV fixed
Apr 15, 2026

Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).This issue affects BC-JAVA: before…

Quick Info

Patch ID: CVE-2026-3505
Vendor: SUSE
Severity: Unknown
CVEs Fixed: 1
Restart: Required

Vendor

SUSE

Additional Info

advisory id: CVE-2026-3505
advisory type: Security Update
cvrf filename: cvrf-CVE-2026-3505.xml

Share