Security: gradle/gradle
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Failure to disable repositories failing to answer can expose builds to malicious artifactsGHSA-mqwm-5m85-gmcv published
Jan 16, 2026 by cobexerHigh -
Failure to disable repositories with unknown host can expose builds to malicious artifactsGHSA-w78c-w6vf-rw82 published
Jan 16, 2026 by cobexerHigh -
Local privilege escalation through system temporary directoryGHSA-465q-w4mf-4f4r published
Feb 25, 2025 by cobexerHigh -
Incorrect permission assignment for symlinked files used in copy or archiving operationsGHSA-43r3-pqhv-f7h9 published
Oct 4, 2023 by ljacometLow -
Possible local text file exfiltration by XML External entity injectionGHSA-mrff-q8qj-xvg8 published
Oct 4, 2023 by ljacometModerate -
Dependency cache path traversalGHSA-2h6c-rv6q-494v published
Jun 30, 2023 by ljacometModerate -
Path traversal vulnerabilities in handling of Tar archivesGHSA-84mw-qh6q-v842 published
Jun 30, 2023 by ljacometModerate -
Dependency verification: Usage of long IDs for PGP keys is unsafe and is subject to collision attacksGHSA-c724-3xg7-g3hf published
Feb 28, 2023 by ljacometModerate -
Dependency verification can ignore checksum verification when signature verification cannot be performedGHSA-j6wc-xfg8-jx2j published
Jul 14, 2022 by ljacometModerate -
Dependency verification can be bypassed when using `ResolutionStrategy.disableDependencyVerification()`GHSA-9pf5-88jw-3qgr published
Feb 10, 2022 by ljacometModerate