Threats Tagged 'ghsa-98j2-6v39-78w8'
View all threats tagged with 'ghsa-98j2-6v39-78w8'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-98j2-6v39-78w8'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-13505: CWE-772 Missing Release of Resource after Effective Lifetime in Legion of the Bouncy Castle Inc. BC-FJACVE-2026-13505 0 Bouncy Castle for Java FIPS (BC-FJA) versions before 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series), and 2.1.3 (2.1.X series) use Object.finalize for zeroising sensitive key material. Finalization timing and order are unspecified and rely on a single finalizer thread, which can cause delays in zeroisation and lead to sensitive key material remaining in memory longer than intended. This behavior can cause increased memory usage and potential OutOfMemoryError under load. The issue affects Java versions later than 11 where finalization is deprecated. The zeroisation mechanism has been updated to use java.lang.ref.Cleaner on Java 9 and later, avoiding reliance on finalization. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected as they do not use this finalizer-based zeroisation. Join the discussion | GCVE Database | 08/08/2026, 00:59:40 UTC Added: 08/08/2026, 14:51:51 UTC |
Showing 1 to 1 of 1 result