bcprov-jdk18on is vulnerable to Uncontrolled Resource Consumption
87
High Risk
HSS/LMS public-key parsing accepts an unbounded level count from the encoded key and allocates structures sized by that count during verify. A crafted public key can force huge allocations. Verifiers that accept untrusted HSS keys are exposed to denial of service. The fix bounds the HSS level count before allocation.
You are affected if you are using a version that falls within the vulnerable range and you verify HSS/LMS signatures or parse untrusted HSS public keys.
bcprov-jdk18on is vulnerable to Uncontrolled Resource Consumption in versions 1.65.0 - 1.84.0.
Upgrade the org.bouncycastle:bcprov-jdk18on and/or the org.bouncycastle:bcprov-jdk15to18 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant