Severity: moderate 

Affected versions:

- Apache Kerby (org.apache.kerby:kerby-asn1) before 2.1.2

Description:

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, 
it's possible to trigger a StackOverFlow Exception which can lead to denial of 
service issues. Users are recommended to upgrade to version 2.1.2, which fixes 
this issue.

References:

https://directory.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-57914

Reply via email to