CVE Tools

Gradle

24 CVEs tracked since 2017. Since Feb 2017, none of them reached CISA KEV.

Gradle CVEs per month

Feb 2017 to Mar 2022. Point at a month, or focus the strip and use the arrow keys.
Gradle CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0210
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09100
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-0430
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-0940
2021-1030
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-0330

Products

The products that kept showing up in Gradle's monthly top three, with their CVEs summed over those months.

  1. Enterprise163 months
  2. Gradle83 months
  3. Enterprise Cache Node21 month
  4. Build Cache Node11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Gradle.

  1. CVE-2026-25063gradle-completion has a Bash command injection issue—
  2. CVE-2026-22865Gradle's failure to disable repositories failing to answer can expose builds to malicious artifacts7.4
  3. CVE-2026-22816Gradle fails to disable repositories which can expose builds to malicious artifacts7.4
  4. CVE-2025-27148Gradle vulnerable to local privilege escalation through system temporary directory8.8
  5. CVE-2025-24858Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by...—
  6. CVE-2024-46881Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration func...7.1
  7. CVE-2023-49238In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Alth...9.8
  8. CVE-2023-42445Possible local file exfiltration by XML External entity injection6.8
  9. CVE-2023-44387Gradle has incorrect permission assignment for symlinked files used in copy or archiving operations3.2
  10. CVE-2023-35946Dependency cache path traversal in Gradle6.9
  11. CVE-2023-35947Path traversal vulnerabilities in handling of Tar archives in Gradle6.9
  12. CVE-2023-30853Gradle Build Action data written to GitHub Actions Cache may expose secrets7.6
  13. CVE-2023-26053Gradle usage of long IDs for PGP keys opens potential for collision attacks6.6
  14. CVE-2022-41575A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext cred...7.5
  15. CVE-2022-41574An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured...7.5

The record

Peak rank
#45 in Sep 2020
Busiest month shown
Sep 2020, 10 CVEs
Months with a KEV entry
0 since Feb 2017
Monthly snapshots
6 since 2017
Gradle's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store