[
https://issues.apache.org/jira/browse/CAMEL-25468?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-25468.
---------------------------------
Resolution: Fixed
> Upgrade Bouncy Castle to 1.86 on Camel 4.22.x
> ---------------------------------------------
>
> Key: CAMEL-25468
> URL: https://issues.apache.org/jira/browse/CAMEL-25468
> Project: Camel
> Issue Type: Dependency upgrade
> Components: build system, camel-pqc
> Affects Versions: 4.22.0, 4.22.1
> Reporter: Roman Stepaniuk
> Priority: Major
> Fix For: 4.22.2
>
>
> Backport the Bouncy Castle 1.86 upgrade and the required camel-pqc
> compatibility changes to Camel 4.22.x, targeting release 4.22.2.
> Security rationale
> Camel 4.22.0 and 4.22.1 use Bouncy Castle 1.85. The vendor advisories
> identify regular Bouncy Castle Java versions before 1.86 as affected and 1.86
> as the fixed version for the following published CVEs. Therefore, upgrading
> to 1.85.2 would not provide these fixes:
> - CVE-2026-18036:
> https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9018036
> - CVE-2026-18040:
> https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9018040
> - CVE-2026-17508:
> https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9017508
> - CVE-2026-85515:
> https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9085515
> - CVE-2026-97873:
> https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9097873
> Compatibility and migration
> Bouncy Castle 1.86 removes legacy post-quantum implementations and
> parameter-spec classes, requiring the following camel-pqc changes:
> - Remove the PICNIC signatureAlgorithm value, PQCSignatureAlgorithms.PICNIC
> and PQCDefaultPicnicMaterial.
> - Move CMCE and FRODO from BCPQC to the BC provider.
> - Change lifecycle-manager defaults from mceliece348864 to mceliece460896 and
> from frodokem640aes to frodokem976aes.
> - Regenerate stored CMCE, FRODO and Picnic keys and update the peers they are
> shared with.
> - Use standardized parameter-set names for DILITHIUM and SPHINCSPLUS. The
> dilithium2, dilithium3 and dilithium5 names are no longer accepted; the
> sha2_128s alias remains supported.
> These breaking changes are documented in the component documentation and the
> Camel 4.22.2 upgrade-guide entry on main.
> Related pull requests
> Original implementation on main:
> https://github.com/apache/camel/pull/27052
> Camel 4.22.x backport:
> https://github.com/apache/camel/pull/27500
> Camel 4.22.2 upgrade guide and documentation/test follow-up:
> https://github.com/apache/camel/pull/27562
> Requested fix version: 4.22.2.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)