StackRadar

CVE-2026-3505

High

Advisory

Published 15 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
35
deployed by those charts
Fix available
2 of 4
affected packages

Bouncy Castle Uncontrolled Resource Consumption vulnerability

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 35 images.

Affected packageAffected versionsFixed inImages
bcpg-jdk15onmaven1.50, 1.51, 1.56, 1.59+7 moreno fix listed27
bcpg-jdk18onmaven1.78.1, 1.80, 1.821.845
bcpg-jdk15to18maven1.65, 1.751.842
bouncycastledeb1.61-1no fix listed1
OSV records
GHSA-cj8j-37rh-8475UBUNTU-CVE-2026-3505

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
bcpg-jdk15on@1.69
no fix listed

Open the chart page →

7,713
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
bouncycastle@1.61-1
no fix listed

Open the chart page →

24,488
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
bcpg-jdk18on@1.78.1
1.84

Open the chart page →

5,398
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
bcpg-jdk15on@1.61
no fix listed

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
bcpg-jdk15on@1.66
no fix listed

Open the chart page →

6,531
elasticsearch-dataempathyco0.2.01 of 2See more

elasticsearch-data empathyco 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
bcpg-jdk15on@1.59
no fix listed

Open the chart page →

3,703
elasticsearch-masterempathyco0.3.01 of 2See more

elasticsearch-master empathyco 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
bcpg-jdk15on@1.59
no fix listed

Open the chart page →

3,703
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
bcpg-jdk15on@1.69
no fix listed

Open the chart page →

4,621
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
bcpg-jdk18on@1.80
1.84

Open the chart page →

2,406
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
bcpg-jdk15on@1.69
no fix listed

Open the chart page →

7,713
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
bcpg-jdk15on@1.69
no fix listed

Open the chart page →

13,352
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
bcpg-jdk15on@1.56
no fix listed

Open the chart page →

23,665
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
bcpg-jdk18on@1.82
1.84

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
bcpg-jdk18on@1.82
1.84

Open the chart page →

5,238
cp-helm-chartscp-helm-charts0.6.15 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

5 of the 8 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
bcpg-jdk15on@1.68
no fix listed
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
bcpg-jdk15on@1.68
no fix listed
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
bcpg-jdk15on@1.68
no fix listed
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
bcpg-jdk15on@1.68
no fix listed
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
bcpg-jdk15on@1.68
no fix listed

Open the chart page →

58,857
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
bcpg-jdk18on@1.78.1
1.84

Open the chart page →

5,398
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
bcpg-jdk15on@1.64
no fix listed

Open the chart page →

19,802
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
bcpg-jdk18on@1.82
1.84

Open the chart page →

25,017
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
bcpg-jdk15on@1.68
no fix listed

Open the chart page →

7,144
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
bcpg-jdk15on@1.60
no fix listed

Open the chart page →

39,349
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
bcpg-jdk18on@1.78.1
1.84

Open the chart page →

5,320
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
bcpg-jdk15to18@1.65
1.84

Open the chart page →

12,856
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bcpg-jdk15on@1.62
no fix listed

Open the chart page →

7,929
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
bcpg-jdk15on@1.69
no fix listed

Open the chart page →

6,037
bpjstk-serviceopenshift1.0.02 of 6See more

bpjstk-service openshift 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
andrianrf/iso-client:latestba560086ce15
bcpg-jdk15on@1.51
no fix listed
andrianrf/iso-server:latest7da47f525c7d
bcpg-jdk15on@1.51
no fix listed

Open the chart page →

34,671
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
bcpg-jdk15on@1.50
no fix listed

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
bcpg-jdk15on@1.50
no fix listed

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
bcpg-jdk15on@1.50
no fix listed

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
bcpg-jdk15on@1.50
no fix listed

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
bcpg-jdk15on@1.50
no fix listed

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
bcpg-jdk15on@1.50
no fix listed

Open the chart page →

13,100
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
bcpg-jdk15to18@1.75
1.84

Open the chart page →

4,946
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
bcpg-jdk15on@1.69
no fix listed

Open the chart page →

18,756
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-3505.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
bcpg-jdk15on@1.68
no fix listed

Open the chart page →

28,605

Container images carrying it

35 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
apache/nifi-registry:1.26.07cdfd8deec92
bcpg-jdk18on@1.78.1
1.84
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
bcpg-jdk15on@1.59
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
bcpg-jdk18on@1.82
1.84
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
bcpg-jdk15on@1.69
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
bcpg-jdk15on@1.69
no fix listed
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bcpg-jdk15on@1.62
no fix listed
1
andrianrf/iso-client:latestba560086ce15
bcpg-jdk15on@1.51
no fix listed
1
andrianrf/iso-server:latest7da47f525c7d
bcpg-jdk15on@1.51
no fix listed
1
apache/nifi-registry:1.14.0090b7f87ec7f
bcpg-jdk15on@1.69
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
bcpg-jdk18on@1.78.1
1.84
1
apache/nifi-registry:0.8.0974efa2f21da
bcpg-jdk15on@1.66
no fix listed
1
assistiot/identity-manager_kc:latest0df4b4fa899a
bcpg-jdk15on@1.69
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
bouncycastle@1.61-1
no fix listed
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
bcpg-jdk15on@1.68
no fix listed
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
bcpg-jdk15on@1.68
no fix listed
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
bcpg-jdk15on@1.68
no fix listed
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
bcpg-jdk15on@1.68
no fix listed
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
bcpg-jdk15on@1.68
no fix listed
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
bcpg-jdk15on@1.50
no fix listed
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
bcpg-jdk15on@1.50
no fix listed
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
bcpg-jdk15on@1.50
no fix listed
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
bcpg-jdk15on@1.50
no fix listed
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
bcpg-jdk15on@1.50
no fix listed
1
gurolakman/ussigw-core:1.0.48739565c3ea2
bcpg-jdk15on@1.50
no fix listed
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
bcpg-jdk15on@1.60
no fix listed
1
keyfactor/signserver-ce:7.3.2798fbbe00283
bcpg-jdk18on@1.80
1.84
1
openbas/platform:2.0.5d986d80b0a75
bcpg-jdk18on@1.82
1.84
1
rundeck/rundeck:3.2.74d64fe56f767
bcpg-jdk15on@1.64
no fix listed
1
rundeck/rundeck:3.0.16b13e8059ad72
bcpg-jdk15on@1.56
no fix listed
1
sonatype/nexus3:3.58.1586060431b64
bcpg-jdk15to18@1.75
1.84
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
bcpg-jdk15on@1.69
no fix listed
1
wistefan/mvf:lateste0887302b2d8
bcpg-jdk15on@1.68
no fix listed
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
bcpg-jdk15on@1.61
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
bcpg-jdk15to18@1.65
1.84
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
bcpg-jdk15on@1.68
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.