Skip to content

Bump Bouncy Castle 1.86, urllib3 2.8.0, oauthlib 4.0.0 in sample-apps (6 Mend HIGH CVEs) - #2006

Merged
radu-gheorghe merged 1 commit into
masterfrom
fix/cve-deps-2026-09-30
Sep 30, 2026
Merged

radu-gheorghe merged 1 commit into
masterfrom
fix/cve-deps-2026-09-30

Conversation

@odosk

@odosk odosk commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ This PR was created by an AI assistant (Claude). Please review all changes carefully before merging.

Once approved, please merge it — this is an automated dependency-update PR and merging is the final step that closes out the linked Mend/Jira findings.

Summary

Bumps Bouncy Castle to 1.86, urllib3 to 2.8.0 and oauthlib to 4.0.0, plus every other dependency in the touched files, clearing 6 Mend HIGH CVEs (VESPANG-3395).

Changed Files

examples/operations/monitoring/album-recommendation-monitoring/album-recommendation-random-data/pom.xml

  • bcprov-jdk18on: 1.85.2 → 1.86 (CVE-2026-17508, CVE-2026-71889)
  • bcpkix-jdk18on, bcutil-jdk18on: 1.85 → 1.86
  • maven-compiler-plugin: 3.15.0 → 3.16.0

examples/book-search/pom.xml

  • bcpkix-jdk18on: 1.85 → 1.86 (CVE-2026-17508, CVE-2026-71888, CVE-2026-71889)
  • bcprov-jdk18on: 1.85.2 → 1.86; bcutil-jdk18on: 1.85 → 1.86
  • jackson-databind: 2.22.2 → 2.22.3; logback-classic: 1.6.3 → 1.6.4; maven-surefire-plugin: 3.5.2 → 3.6.0

examples/clients/client-java/app/build.gradle.kts (same Bouncy Castle 1.85 constraints)

  • bcprov-jdk18on, bcpkix-jdk18on, bcutil-jdk18on: → 1.86
  • ayza-for-pem: 10.0.6 → 10.1.0; jetty-client, jetty-http2-client-transport: 12.1.12 → 12.1.13; slf4j-simple: 2.0.18 → 2.0.20

examples/book-search/frontend/uv.lock — regenerated via uv lock --upgrade:

  • urllib3: 2.7.0 → 2.8.0 (CVE-2026-97687, CVE-2026-97689)
  • streamlit 1.62.0 → 1.64.0, pyvespa 1.2.4 → 1.2.7, plus minor/patch bumps

visual-retrieval-colpali/src/legacy-requirements.txt — swept via bump_requirements.py (62 pins):

  • urllib3: 2.7.0 → 2.8.0 (CVE-2026-97687, CVE-2026-97689)
  • oauthlib: 3.3.1 → 4.0.0 (CVE-2026-49265)
  • peft 0.20.0 → 0.21.1, tokenizers 0.23.1 → 0.23.2, transformers → 5.17.0, torch → 2.14.0, colpali-engine → 0.3.18

CVEs Addressed

Verified against NVD / GHSA / OSV.dev:

Package CVE(s) Severity Fix version reached
bcprov-jdk18on CVE-2026-17508 HIGH 1.86
bcprov-jdk18on CVE-2026-71889 HIGH 1.86
bcpkix-jdk18on CVE-2026-17508 HIGH 1.86
bcpkix-jdk18on CVE-2026-71888 HIGH 1.86
bcpkix-jdk18on CVE-2026-71889 HIGH 1.86
urllib3 CVE-2026-97687 HIGH 2.8.0
urllib3 CVE-2026-97689 HIGH 2.8.0
oauthlib CVE-2026-49265 HIGH 4.0.0

⚠️ Cannot fix in this PR

  • tokenizers CVE-2026-85670: no stable release after 0.23.2 (1.0.0rc2 is a pre-release).
  • peft CVE-2026-71281: tags v0.20.0 and v0.21.1 still call torch.load without weights_only in corda.py and loraga.py; no fixed release yet.
  • langchain-community CVE-2026-72848 (examples/agentic-streamlit-chatbot/advanced_app/requirements.txt): last affected version 0.4.2 is the latest stable release; only 1.0.0a1 (pre-release) is newer.

Implementation Notes

  • legacy-requirements.txt was already unresolvable on master: vidore-benchmark needs transformers<5 and sentence-transformers<4, google-generativeai needs protobuf<6, datasets caps fsspec, and pydantic pins an exact pydantic-core. This PR bumps pins the same way e85098e did and does not re-resolve; a full re-resolve would downgrade 20 packages, including sentence-transformers below the CVE-2026-68770 fix.
  • vespa_version (vespa-feed-client) left as-is. JUnit kept on 5.14.4 (latest 5.x); 6.x is a major bump that could not be test-compiled here.
  • oauthlib 4.0.0: its only dependent here, python-fasthtml, has no upper bound.

Verification

  • Pre-existing CI failure: test / htmlproofer fails on an external 404 (https://search.vespa.ai/search?query=using%20multiple%20threads%20per%20search) in content this PR does not touch. The master Link checker also fails, so it is pre-existing.
  • mvn -B -q package -DskipTests (album-recommendation-random-data) in maven:3-eclipse-temurin-17: success; dependency:list shows Bouncy Castle 1.86
  • mvn -B compile (book-search): success. Tests not run: they need the internal vespa-testcontainers artifact, which is not on Maven Central
  • gradle build -x test (client-java) in gradle:9-jdk21: success; runtime classpath resolves bcpkix-jdk18on:1.84 -> 1.86
  • uv lock --upgrade (book-search frontend) in a throwaway uv container
  • grep shows urllib3 2.8.0 in both Python files; no downgrades in either
  • Re-run the Mend scan after merge to confirm the listed CVEs clear

PR authored by the auto security-workflow skill.

🤖 Generated with Claude Code

Bouncy Castle 1.86 (CVE-2026-17508, CVE-2026-71888, CVE-2026-71889), urllib3 2.8.0 (CVE-2026-97687, CVE-2026-97689), oauthlib 4.0.0 (CVE-2026-49265). VESPANG-3395.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@odosk odosk added the auto security Automated security created PRs label Sep 30, 2026
@odosk
odosk marked this pull request as ready for review September 30, 2026 10:47

@radu-gheorghe radu-gheorghe left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This further breaks the already broken visual-retrieval-colpali/src/legacy-requirements.txt

I'm going to merge this and open a PR to remove the pip path that is broken before this PR anyway.

@radu-gheorghe
radu-gheorghe merged commit 15c175c into master Sep 30, 2026
8 of 9 checks passed
@radu-gheorghe
radu-gheorghe deleted the fix/cve-deps-2026-09-30 branch September 30, 2026 11:46

This branch was successfully deployed

1 active deployment
Vespa Cloud CD — babe1fdd Deployed Sep 30, 2026 by odosk via Push to Vespa Cloud #1382
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto security Automated security created PRs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants