Intel

AIKIDO-2026-312722

bcmls-jdk18on is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-17507 Published Yesterday

75

High Risk

This Affects:

JAVAbcmls-jdk18on
1.78 - 1.85
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

MLS membership checks treat a wire-format unsigned leaf index as a signed value, so an out-of-range sender enters non-terminating tree-path processing and exhausts memory. The fix converts leaf indexes to unsigned values before both membership comparisons.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you process MLS private messages or Remove proposals from group members.

Background info

bcmls-jdk18on is vulnerable to Uncontrolled Resource Consumption in versions 1.78 - 1.85.

How to fix this

Upgrade the bcmls-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform