CVE-2020-7226: Allocation of Resources Without Limits or Throttling
(updated )
CiphertextHeader.java
allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with new byte
may depend on untrusted input within the header of encoded data.
References
Detect and mitigate CVE-2020-7226 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →