Skip to content

[Aikido] Fix security issue in bigdecimal via minor version upgrade from 4.1.2 to 4.1.3 in docs - #24

Closed
aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-121413015-5jyh
Closed

aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-121413015-5jyh

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Upgrade BigDecimal to fix heap buffer overflow in division operations that could cause memory corruption through out-of-bounds memory access.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-401924
LOW
[bigdecimal] A heap buffer overflow in the Newton-Raphson division algorithm allows attackers to corrupt adjacent memory through out-of-bounds memcpy operations, potentially enabling remote code execution or denial of service.

@dzikowski dzikowski closed this Sep 22, 2026
@dzikowski
dzikowski deleted the fix/aikido-security-update-packages-121413015-5jyh branch September 22, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant