bcmls-jdk18on is vulnerable to Security Vulnerability
87
High Risk
The MLS hash-ratchet (GroupKeySet) honours an arbitrary 32-bit generation counter supplied by the sender when advancing keys. A peer can force a huge generation jump and trigger excessive ratchet computation or memory use. MLS sessions that process untrusted generation counters are exposed to denial of service. The fix limits acceptable generation-counter advancement.
You are affected if you are using a version that falls within the vulnerable range and you process MLS group key ratcheting with peer-supplied generation counters.
bcmls-jdk18on is vulnerable to Security Vulnerability in versions 1.73.0 - 1.84.0.
Upgrade the org.bouncycastle:bcmls-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant