binance / binance/binance-connector-java

Dependency maven:org.bouncycastle:bcprov-jdk18on:1.78 is vulnerable

Open
#200 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
581
Forks
255
Avg merge
2m
Merged PRs (30d)
2

Description

Hi!
There is a vulnerability in latest version dependency.
Details:

> Dependency maven:org.bouncycastle:bcprov-jdk18on:1.78 is vulnerable
>
> Update to unaffected version 1.78.1
>
> CVE-2025-8916, Score: 5.3
>
> Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
>
> Read More: https://www.mend.io/vulnerability-database/CVE-2025-8916
>
> Results powered by Mend.io

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.