Skip to content

fix: upgrade bouncy castle dependency to address CVE-2025-8916#80

Merged
Meenu-Mariya merged 1 commit into
ibm-messaging:mainfrom
Meenu-Mariya:issue-79
Feb 10, 2026
Merged

fix: upgrade bouncy castle dependency to address CVE-2025-8916#80
Meenu-Mariya merged 1 commit into
ibm-messaging:mainfrom
Meenu-Mariya:issue-79

Conversation

@Meenu-Mariya
Copy link
Copy Markdown
Contributor

Description

  • Upgraded com.ibm.mq:com.ibm.mq.allclient from 9.4.0.5 to 9.4.4.1
  • This resolves CVE-2025-8916 in org.bouncycastle:bcprov-jdk18on
  • Bouncy Castle upgraded from 1.78.1 (vulnerable) to 1.81 (fixed)

Fixes (#79)

Signed-off-by: Meenu Mariya meenu.mariya@ibm.com

Comment thread pom.xml
CVE-2025-8916

- Upgraded com.ibm.mq:com.ibm.mq.allclient from 9.4.0.5 to 9.4.4.1
- This resolves CVE-2025-8916 in org.bouncycastle:bcprov-jdk18on
- Bouncy Castle upgraded from 1.78.1 (vulnerable) to 1.81 (fixed)
- All unit tests pass successfully
- Updated MQ_IMAGE from 9.4.0.5-r2 to 9.4.4.1-r1 in AbstractJMSContextIT
- Ensures integration tests run against matching MQ server version

Signed-off-by: Meenu Mariya <meenu.mariya@ibm.com>
@Meenu-Mariya Meenu-Mariya merged commit db45f7b into ibm-messaging:main Feb 10, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants