Skip to content

fix(deps): update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [security] - #379

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability
Open

fix(deps): update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [security]#379
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.bouncycastle:bcpkix-jdk18on (source) 1.78.11.84 age confidence

Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation

CVE-2025-8916 / GHSA-4cx2-fc23-5wg6

More information

Details

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertP... https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.java , https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathRevi... https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.java .

This issue affects Bouncy Castle for Java: from BC 1.44 through 1.78, from BCPKIX FIPS 1.0.0 through 1.0.7, from BCPKIX FIPS 2.0.0 through 2.0.7.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:P/R:U/RE:M/U:Amber

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

CVE-2026-5588 / GHSA-wg6q-6289-32hp

More information

Details

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team July 24, 2026 13:15
@renovate renovate Bot added dependencies Dependency updates java Java / Gradle dependencies labels Jul 24, 2026
@renovate renovate Bot added the java Java / Gradle dependencies label Jul 24, 2026
@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown

Test Results

675 tests   675 ✅  2m 26s ⏱️
114 suites    0 💤
114 files      0 ❌

Results for commit ae24c0d.

♻️ This comment has been updated with latest results.

jonbartels
jonbartels previously approved these changes Jul 24, 2026
@jbeckers

Copy link
Copy Markdown
Contributor

Should go in together with #380

@renovate
renovate Bot force-pushed the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch from 3b467ff to 17df5db Compare July 24, 2026 23:09
mgaffigan
mgaffigan previously approved these changes Jul 24, 2026
@renovate
renovate Bot force-pushed the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch 2 times, most recently from 18404ca to 8078156 Compare July 27, 2026 13:26
@renovate
renovate Bot dismissed stale reviews from jonbartels and mgaffigan via 8d3f12f July 28, 2026 13:31
@renovate
renovate Bot force-pushed the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch 3 times, most recently from 6a25f3f to af6fef9 Compare July 31, 2026 00:36
@renovate
renovate Bot force-pushed the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch from af6fef9 to ae24c0d Compare August 16, 2026 00:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates java Java / Gradle dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants