bcutil-jdk18on is vulnerable to Uncontrolled Recursion
87
High Risk
OERInputStream recurses without a depth limit when decoding self-referential IEEE 1609.2 OER schemas. Crafted OER input can recurse until the stack is exhausted. Parsers handling untrusted 1609.2/OER data can crash or hang. The fix enforces a maximum OER recursion depth.
You are affected if you are using a version that falls within the vulnerable range and you parse untrusted IEEE 1609.2 OER with OERInputStream.
bcutil-jdk18on is vulnerable to Uncontrolled Recursion in versions 1.70.0 - 1.84.0.
Upgrade the org.bouncycastle:bcutil-jdk18on and/or the org.bouncycastle:bcutil-jdk15to18 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant