GHSA-cj8j-37rh-8475
Bouncy Castle Uncontrolled Resource Consumption vulnerability
Quick fix
GHSA-cj8j-37rh-8475 — org.bouncycastle:bcpg-jdk14: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpg-jdk14Details
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This issue affects BC-JAVA before 1.84.
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for org.bouncycastle:bcpg-jdk12 (maven). Pin to a known-safe version or switch to an alternative.
0Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpg-jdk140No fixed version published yet for org.bouncycastle:bcpg-jdk15 (maven). Pin to a known-safe version or switch to an alternative.
0Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpg-jdk15to180No fixed version published yet for org.bouncycastle:bcpg-jdk15on (maven). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for org.bouncycastle:bcpg-jdk16 (maven). Pin to a known-safe version or switch to an alternative.
0Fixed in: 1.84# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpg-jdk18on