Description of the Issue
Description
The latest release of com.box:box-java-sdk relies on a version of org.bouncycastle:bcprov-jdk18on affected by CVE-2026-58062. Updating dependencies within consuming projects does not resolve the issue, as an updated SDK release addressing this dependency bound is not yet available.
Vulnerability Summary
⚬ Affected Package: com.box:box-java-sdk
⚬ Vulnerable Dependency: org.bouncycastle:bcprov-jdk18on
⚬ CVE Identifier: CVE-2026-58062
Expected Behavior
com.box:box-java-sdk should release a patch version that updates org.bouncycastle:bcprov-jdk18on to a secure version, resolving CVE-2026-58062.
Escalation & Clarifications Requested
- Release Timeline: When does the product/engineering team plan to release an updated version of com.box:box-java-sdk containing the patch for this vulnerability?
- Interim Safe Usage Guidance: What is the official recommendation for using com.box:box-java-sdk safely in production environments while this dependency issue remains unpatched in the SDK release?
Description of the Issue
Description
The latest release of com.box:box-java-sdk relies on a version of org.bouncycastle:bcprov-jdk18on affected by CVE-2026-58062. Updating dependencies within consuming projects does not resolve the issue, as an updated SDK release addressing this dependency bound is not yet available.
Vulnerability Summary
⚬ Affected Package: com.box:box-java-sdk
⚬ Vulnerable Dependency: org.bouncycastle:bcprov-jdk18on
⚬ CVE Identifier: CVE-2026-58062
Expected Behavior
com.box:box-java-sdk should release a patch version that updates org.bouncycastle:bcprov-jdk18on to a secure version, resolving CVE-2026-58062.
Escalation & Clarifications Requested