Package
logstash-fips-9.4
Component
bcprov-jdk18on
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-8763 (GHSA-9pwp-9qqc-pr26) is a Bouncy Castle Name Constraints bypass via a trailing dot in rfc822Name/URI fields, fixed in bcprov-jdk18on 1.85. The bundled jruby-openssl gem resolves its four Bouncy Castle jars through a single hardcoded version constant rather than a filesystem scan, so the vulnerable jar can't be swapped in place without also patching that constant and its three sibling jars — a coordinated update only a newer jruby-openssl release (0.16.2+) currently carries.
Status