Skip to content

MODLOGSAML-220: Bump bcprov-jdk18on and bcpkix-jdk18on to 1.83#215

Merged
julianladisch merged 1 commit intomasterfrom
MODLOGSAML-220
Mar 12, 2026
Merged

MODLOGSAML-220: Bump bcprov-jdk18on and bcpkix-jdk18on to 1.83#215
julianladisch merged 1 commit intomasterfrom
MODLOGSAML-220

Conversation

@julianladisch
Copy link
Copy Markdown
Contributor

https://folio-org.atlassian.net/browse/MODLOGSAML-220

Upgrade

  • org.bouncycastle:bcpkix-jdk18on
  • org.bouncycastle:bcprov-jdk18on

from 1.78.1 to 1.83.

This fixes this security vulnerability:

Previously we used a more recent cryptacular version to transitively bump the two bouncycastle dependencies; however, only cryptacular >= 1.3.0 comes with bouncycastle >= 1.79. We want to avoid this minor version bump that has too many code changes: vt-middleware/cryptacular@v1.2.7...v1.3.0

… 1.83 - CVE-2025-8916

https://folio-org.atlassian.net/browse/MODLOGSAML-220

Upgrade

* org.bouncycastle:bcpkix-jdk18on
* org.bouncycastle:bcprov-jdk18on

from 1.78.1 to 1.83.

This fixes this security vulnerability:

* GHSA-4cx2-fc23-5wg6 = CVE-2025-8916 ASN.1 with huge name length causes excessive resource consumption in PKIXCertPathReviewer

Previously we used a more recent cryptacular version to transitively bump the two bouncycastle dependencies;
however, only cryptacular >= 1.3.0 comes with bouncycastle >= 1.79. We want to avoid this minor version bump
that has too many code changes: vt-middleware/cryptacular@v1.2.7...v1.3.0
@sonarqubecloud
Copy link
Copy Markdown

@julianladisch julianladisch merged commit bad2ce0 into master Mar 12, 2026
5 checks passed
@julianladisch julianladisch deleted the MODLOGSAML-220 branch March 12, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants