Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method expandSize(int newPos) of class org.apache.xml.security.utils.UnsyncByteArrayOutputStream goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.
{
"github_reviewed": true,
"nvd_published_at": "2013-10-16T17:55:00Z",
"github_reviewed_at": "2022-11-08T14:57:18Z",
"severity": "MODERATE",
"cwe_ids": []
}