HADOOP-19866. Upgrade bouncycastle to 1.84 for security (#8443)


CVE-2025-14813 - GOSTCTR implementation unable to process more than 255 blocks correctly.
CVE-2026-0636 - LDAP Injection Vulnerability in LDAPStoreHelper.java.
CVE-2026-3505 - Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-5588 - PKIX draft CompositeVerifier accepts empty signature sequence as valid.
CVE-2026-5598 - Non-constant time comparisons risk private key leakage in FrodoKEM.


Contributed by PJ Fanning
3 files changed