Package
zipkin
Component
bcprov-jdk18on
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
GHSA-qp49-qgx5-5m26 (CVE-2026-13506) requires bcprov-jdk18on 1.85. This component is Apache Pulsar's own vendored jar-in-jar loader (org.apache.pulsar:bouncy-castle-bc) that embeds bcprov-jdk18on directly rather than resolving it as a transitive Maven dependency, so the version cannot be overridden by a downstream dependency-management patch. The latest published release of the loader artifact, 4.2.4, still bundles the vulnerable 1.84 copy; this remains pending until Apache Pulsar publishes a release with a patched Bouncy Castle version embedded.
Status