Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
2.5.13, 2.7.8, 2.8.3
-
None
-
None
-
CVE-2026-3505, CVE-2026-5598
Description
Current Situation
Currently JS7 components Controller, Agent and JOC Cockpit ship with bouncycastle libraries 1.81 (2.5.x and 2.7.x releases) and 1.82 (2.8.x releases). These libraries are affected by the vulnerability.
Currently we rate the impact of the vulnerability to be low. Also, no official impact rating has been publicly provided yet.
Desired Behavior
JS7 components Controller, Agent and JOC Cockpit should ship with bouncycastle version 1.84 that fixes the issue.
Immediate Measures
Customers can replace the existing bouncycastle libraries with the current version of these libraries.
Releases 2.5.x
- bcpkix-jdk18on
- bcpg-jdk18on
- bcprov-jdk18on
- bcutil-jdk18on
Releases 2.7.x and 2.8.x
- bcpkix-jdk18on
- bcpg-jdk18on
- bcprov-jdk18on
- bcutil-jdk18on