Bump Bouncy Castle 1.86, urllib3 2.8.0, oauthlib 4.0.0 in sample-apps (6 Mend HIGH CVEs) - #2006
Merged
Merged
Conversation
Bouncy Castle 1.86 (CVE-2026-17508, CVE-2026-71888, CVE-2026-71889), urllib3 2.8.0 (CVE-2026-97687, CVE-2026-97689), oauthlib 4.0.0 (CVE-2026-49265). VESPANG-3395. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
radu-gheorghe
approved these changes
Sep 30, 2026
radu-gheorghe
left a comment
Contributor
There was a problem hiding this comment.
This further breaks the already broken visual-retrieval-colpali/src/legacy-requirements.txt
I'm going to merge this and open a PR to remove the pip path that is broken before this PR anyway.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bumps Bouncy Castle to 1.86, urllib3 to 2.8.0 and oauthlib to 4.0.0, plus every other dependency in the touched files, clearing 6 Mend HIGH CVEs (VESPANG-3395).
Changed Files
examples/operations/monitoring/album-recommendation-monitoring/album-recommendation-random-data/pom.xmlbcprov-jdk18on:1.85.2→1.86(CVE-2026-17508, CVE-2026-71889)bcpkix-jdk18on,bcutil-jdk18on:1.85→1.86maven-compiler-plugin:3.15.0→3.16.0examples/book-search/pom.xmlbcpkix-jdk18on:1.85→1.86(CVE-2026-17508, CVE-2026-71888, CVE-2026-71889)bcprov-jdk18on:1.85.2→1.86;bcutil-jdk18on:1.85→1.86jackson-databind:2.22.2→2.22.3;logback-classic:1.6.3→1.6.4;maven-surefire-plugin:3.5.2→3.6.0examples/clients/client-java/app/build.gradle.kts(same Bouncy Castle 1.85 constraints)bcprov-jdk18on,bcpkix-jdk18on,bcutil-jdk18on: →1.86ayza-for-pem:10.0.6→10.1.0;jetty-client,jetty-http2-client-transport:12.1.12→12.1.13;slf4j-simple:2.0.18→2.0.20examples/book-search/frontend/uv.lock— regenerated viauv lock --upgrade:urllib3:2.7.0→2.8.0(CVE-2026-97687, CVE-2026-97689)streamlit1.62.0→1.64.0,pyvespa1.2.4→1.2.7, plus minor/patch bumpsvisual-retrieval-colpali/src/legacy-requirements.txt— swept viabump_requirements.py(62 pins):urllib3:2.7.0→2.8.0(CVE-2026-97687, CVE-2026-97689)oauthlib:3.3.1→4.0.0(CVE-2026-49265)peft0.20.0→0.21.1,tokenizers0.23.1→0.23.2,transformers→5.17.0,torch→2.14.0,colpali-engine→0.3.18CVEs Addressed
Verified against NVD / GHSA / OSV.dev:
tokenizersCVE-2026-85670: no stable release after 0.23.2 (1.0.0rc2 is a pre-release).peftCVE-2026-71281: tags v0.20.0 and v0.21.1 still calltorch.loadwithoutweights_onlyincorda.pyandloraga.py; no fixed release yet.langchain-communityCVE-2026-72848 (examples/agentic-streamlit-chatbot/advanced_app/requirements.txt): last affected version 0.4.2 is the latest stable release; only 1.0.0a1 (pre-release) is newer.Implementation Notes
legacy-requirements.txtwas already unresolvable on master:vidore-benchmarkneedstransformers<5andsentence-transformers<4,google-generativeaineedsprotobuf<6,datasetscapsfsspec, andpydanticpins an exactpydantic-core. This PR bumps pins the same way e85098e did and does not re-resolve; a full re-resolve would downgrade 20 packages, includingsentence-transformersbelow the CVE-2026-68770 fix.vespa_version(vespa-feed-client) left as-is. JUnit kept on 5.14.4 (latest 5.x); 6.x is a major bump that could not be test-compiled here.oauthlib4.0.0: its only dependent here,python-fasthtml, has no upper bound.Verification
test / htmlprooferfails on an external 404 (https://search.vespa.ai/search?query=using%20multiple%20threads%20per%20search) in content this PR does not touch. The master Link checker also fails, so it is pre-existing.mvn -B -q package -DskipTests(album-recommendation-random-data) inmaven:3-eclipse-temurin-17: success;dependency:listshows Bouncy Castle 1.86mvn -B compile(book-search): success. Tests not run: they need the internalvespa-testcontainersartifact, which is not on Maven Centralgradle build -x test(client-java) ingradle:9-jdk21: success; runtime classpath resolvesbcpkix-jdk18on:1.84 -> 1.86uv lock --upgrade(book-search frontend) in a throwaway uv containergrepshowsurllib32.8.0 in both Python files; no downgrades in eitherPR authored by the auto security-workflow skill.
🤖 Generated with Claude Code