Skip to content

Security: Transitive dependency vulnerability in org.bouncycastle:bcprov-jdk18on (CVE-2026-58062) Component: com.box:box-java-sdk #1970

Description

@sapirgolan
  • I have checked that the [SDK documentation][sdk-docs] doesn't solve my issue.
  • I have checked that the [API documentation][api-docs] doesn't solve my issue.
  • I have searched the [Box Developer Forums][dev-forums] and my issue isn't already reported (or if it has been reported, I have attached a link to it, for reference).
  • I have searched [Issues in this repo][github-repo] and my issue isn't already reported.

Description of the Issue

Description
The latest release of com.box:box-java-sdk relies on a version of org.bouncycastle:bcprov-jdk18on affected by CVE-2026-58062. Updating dependencies within consuming projects does not resolve the issue, as an updated SDK release addressing this dependency bound is not yet available.
Vulnerability Summary
⚬ Affected Package: com.box:box-java-sdk
⚬ Vulnerable Dependency: org.bouncycastle:bcprov-jdk18on
⚬ CVE Identifier: CVE-2026-58062
Expected Behavior
com.box:box-java-sdk should release a patch version that updates org.bouncycastle:bcprov-jdk18on to a secure version, resolving CVE-2026-58062.
Escalation & Clarifications Requested

  1. Release Timeline: When does the product/engineering team plan to release an updated version of com.box:box-java-sdk containing the patch for this vulnerability?
  2. Interim Safe Usage Guidance: What is the official recommendation for using com.box:box-java-sdk safely in production environments while this dependency issue remains unpatched in the SDK release?

Metadata

Metadata

Labels

bugAdded to issues that describes SDK bug

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions