CVE detail
CVE-2026-3505
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3505.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 15, 2026, 10:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2458638bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 15, 2026, 10:16 AM - https://access.redhat.com/security/cve/CVE-2026-3505access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 15, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:18059access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 15, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:18055access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 15, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:18054access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 15, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:17668access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 15, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:13631access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 15, 2026, 10:16 AM No excerpt available.
Exploitgithub.comApr 15, 2026, 10:16 AMNo excerpt available.
Exploitgithub.comApr 15, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14257CVSS 7.5 · High
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but…
- CVE-2026-55831CVSS 7.5 · High
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-dec…
- CVE-2026-53596CVSS 5.3 · Medium
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on t…
- CVE-2026-45713CVSS 7.5 · High
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA pay…
- CVE-2026-44891CVSS 7.5 · High
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecode…
- CVE-2026-54340CVSS 7.5 · High
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplifi…