Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Disclosure

#25048of 53,619
9.8Total CVSS
Vulnerabilities · 1
PT-2026-33030
9.8
2026-04-15
Bouncy Castle · Bc-Java · CVE-2026-3505
**Name of the Vulnerable Software and Affected Versions** BC-JAVA versions prior to 1.84 **Description** An issue in the bcpg modules allows for unbounded PGP AEAD chunk size, which can lead to pre-authentication resource exhaustion. Resource exhaustion occurs when a system lacks limits or throttling on resource allocation, allowing a requester to consume all available system memory or CPU. **Recommendations** Update to version 1.84 or later.