bcpg-jdk18on is vulnerable to Uncontrolled Resource Consumption
87
High Risk
Bouncy Castle's OpenPGP user-attribute subpacket parser sizes its buffer from the declared subpacket length before reading the data, bounded only by the JVM heap. A crafted certificate or key with an oversized user-attribute subpacket forces an excessive up-front allocation. This can trigger an out-of-memory condition and crash or freeze the application. The fix bounds the subpacket length before allocation.
You are affected if you are using a version that falls within the vulnerable range and your application parses OpenPGP certificates or keys containing user-attribute subpackets taken from untrusted input.
bcpg-jdk18on is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpg-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant