Skip to content

chore(deps): update bouncycastle.version to v1.84 [security]#2040

Merged
ggrossetie merged 1 commit into
mainfrom
renovate/bouncycastle.version
May 30, 2026
Merged

chore(deps): update bouncycastle.version to v1.84 [security]#2040
ggrossetie merged 1 commit into
mainfrom
renovate/bouncycastle.version

Conversation

@ggrossetie
Copy link
Copy Markdown
Member

@ggrossetie ggrossetie commented Apr 17, 2026

This PR contains the following updates:

Package Type Update Change
org.bouncycastle:bcpkix-jdk18on (source) test minor 1.831.84
org.bouncycastle:bcprov-jdk18on (source) test minor 1.831.84

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

CVE-2026-5588 / GHSA-wg6q-6289-32hp

More information

Details

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Bouncy Castle has an LDAP injection

CVE-2026-0636 / GHSA-c3fc-8qff-9hwx

More information

Details

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.

This issue affects BC-JAVA: from 1.74 before 1.84.

Severity

  • CVSS Score: 5.5 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/RE:M/U:Amber

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Bouncy Castle Has Covert Timing Channel Vulnerability

CVE-2026-5598 / GHSA-p93r-85wp-75v3

More information

Details

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.84.

Severity

  • CVSS Score: 8.9 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/S:P/AU:Y/U:Red

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@ggrossetie ggrossetie added the 🔗 dependencies Pull requests that update a dependency file label Apr 17, 2026
@ggrossetie ggrossetie changed the title chore(deps): update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [security] chore(deps): update bouncycastle.version to v1.84 [security] Apr 18, 2026
@ggrossetie ggrossetie force-pushed the renovate/bouncycastle.version branch from eea336f to 163beb9 Compare May 23, 2026 08:16
@ggrossetie ggrossetie merged commit 3beadfa into main May 30, 2026
6 checks passed
@ggrossetie ggrossetie deleted the renovate/bouncycastle.version branch May 30, 2026 08:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🔗 dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant