CVE Tools

Android Studio

73 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Android Studio, a product in the mobile apps space. Use it to gauge the current risk picture and drill into individual advisories.

Android Studio CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Android Studio CVEs per month
MonthCVEs
2024-103
2024-110
2024-120
2025-010
2025-027
2025-030
2025-040
2025-052
2025-060
2025-071
2025-081
2025-094
2025-1010
2025-110
2025-122
2026-015
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 73 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical57%
  • High2940%
  • Medium3548%
  • Low45%

Latest CVEs

The 15 most recently published vulnerabilities affecting Android Studio.

  1. CVE-2026-1703Limited path traversal when installing wheel archives3.5
  2. CVE-2026-24400AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion7.3
  3. CVE-2026-21945Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java...7.5
  4. CVE-2026-21933Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Ja...6.1
  5. CVE-2026-21932Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle J...7.4
  6. CVE-2026-21925Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: ...4.8
  7. CVE-2025-67735Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder6.5
  8. CVE-2025-66453Rhino vulnerable high CPU usage and potential DoS when passing specific numbers to toFixed() function7.5
  9. CVE-2025-61748Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Jav...3.7
  10. CVE-2025-53066Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE:...7.5
  11. CVE-2025-53057Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java...5.9
  12. CVE-2025-59419Netty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email Forgery5.3
  13. CVE-2025-59734Heap-buffer-overflow write in FFmpeg SANM process_ftch6.4
  14. CVE-2025-59733Heap-buffer-overflow write in FFmpeg EXR dwa_uncompress6.5
  15. CVE-2025-59732Heap-buffer-overflow write in FFmpeg EXR dwa_uncompress6.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store