Skip to content

Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY]#2679

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability
Open

Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY]#2679
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 16, 2026

This PR contains the following updates:

Package Change Age Confidence
org.bouncycastle:bcpkix-jdk18on (source) 1.831.84 age confidence

Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

CVE-2026-5588 / GHSA-wg6q-6289-32hp

More information

Details

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Apr 16, 2026
@renovate renovate Bot requested a review from a team as a code owner April 16, 2026 21:52
@renovate renovate Bot enabled auto-merge (squash) April 16, 2026 21:52
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Apr 16, 2026
@renovate renovate Bot changed the title Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] - autoclosed Apr 23, 2026
@renovate renovate Bot closed this Apr 23, 2026
auto-merge was automatically disabled April 23, 2026 16:44

Pull request was closed

@renovate renovate Bot deleted the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch April 23, 2026 16:44
@renovate renovate Bot changed the title Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] - autoclosed Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] Apr 23, 2026
@renovate renovate Bot reopened this Apr 23, 2026
@renovate renovate Bot force-pushed the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch 2 times, most recently from 95652df to ed9e4d9 Compare April 23, 2026 21:12
@renovate renovate Bot changed the title Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] - autoclosed Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/maven-org.bouncycastle-bcpkix-jdk18on-vulnerability branch 2 times, most recently from ed9e4d9 to d46d846 Compare April 27, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants