Skip to content

Bump org.bouncycastle:bcprov-jdk18on from 1.80 to 1.84 and force org.apache.logging.log4j:log4j-core to 2.25.4 - #1438

Merged
peterzhuamazon merged 1 commit into
opensearch-project:2.19from
shreyah963:cve-fix
Jul 1, 2026
Merged

Bump org.bouncycastle:bcprov-jdk18on from 1.80 to 1.84 and force org.apache.logging.log4j:log4j-core to 2.25.4#1438
peterzhuamazon merged 1 commit into
opensearch-project:2.19from
shreyah963:cve-fix

Conversation

@shreyah963

Copy link
Copy Markdown
Contributor

Description

Fix CVE-2026-0636, CVE-2026-34478, CVE-2026-34477, CVE-2026-34480. Bump org.bouncycastle:bcprov-jdk18on from 1.80 to 1.84 to address GHSA-c3fc-8qff-9hwx (versions >=1.74 <1.84 are vulnerable).

Force org.apache.logging.log4j:log4j-core to 2.25.4 to address GHSA-445c-vh5m-36rj, GHSA-6hg6-v5c8-fphq, and GHSA-3pxv-7cmr-fjr4 (versions <2.25.4 are vulnerable).

Related Issues

Resolves #[Issue number to be closed when this PR is merged]

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

…mp bcprov-jdk18on and force log4j-core

Bump org.bouncycastle:bcprov-jdk18on from 1.80 to 1.84 to address
GHSA-c3fc-8qff-9hwx (versions >=1.74 <1.84 are vulnerable).

Force org.apache.logging.log4j:log4j-core to 2.25.4 to address
GHSA-445c-vh5m-36rj, GHSA-6hg6-v5c8-fphq, and GHSA-3pxv-7cmr-fjr4
(versions <2.25.4 are vulnerable).

Signed-off-by: shreyah963 <shreyab963@gmail.com>
@peterzhuamazon
peterzhuamazon merged commit feec07f into opensearch-project:2.19 Jul 1, 2026
3 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants