binance / binance/binance-connector-java
Dependency maven:org.bouncycastle:bcprov-jdk18on:1.78 is vulnerable
- Dominant language
- Java
- Stars
- 581
- Forks
- 255
- Avg merge
- 2m
- Merged PRs (30d)
- 2
Description
Hi!
There is a vulnerability in latest version dependency.
Details:
> Dependency maven:org.bouncycastle:bcprov-jdk18on:1.78 is vulnerable
>
> Update to unaffected version 1.78.1
>
> CVE-2025-8916, Score: 5.3
>
> Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.
>
> Read More: https://www.mend.io/vulnerability-database/CVE-2025-8916
>
> Results powered by Mend.io
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.