bcpg-jdk15to18 is vulnerable to Denial of Service (DoS)
87
High Risk
The OpenPGP user-attribute subpacket reader in UserAttributeSubpacketInputStream sizes the subpacket body buffer directly from the wire length header. During packet parsing the available-bytes guard returns a value close to the JVM heap size instead of the bytes actually present, potentially leading to memory exhaustion. The fix rejects any subpacket body length above a fixed 2 MiB cap before allocating.
You are affected if you are using a version that falls within the vulnerable range and your application parses OpenPGP certificates, keys, or messages that can originate from untrusted sources.
bcpg-jdk15to18 is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpg-jdk15to18 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant