PT-2026-3330 · Gradle · Gradle
Ljacomet
·
Published
2026-01-16
·
Updated
2026-01-22
·
CVE-2026-22816
CVSS v4.0
8.6
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Gradle versions prior to 9.3.0
Description
Gradle’s native-platform tool, which provides Java bindings for native APIs, does not treat certain exceptions as fatal errors when resolving dependencies in versions before 9.3.0. This allows Gradle to continue to the next repository, potentially resolving dependencies from a different source. Specifically, an unresolvable host name does not halt the process, allowing an attacker to register a service under the build’s host name and serve malicious artifacts if the malicious repository is listed before others in the build configuration.
Recommendations
Update to Gradle version 9.3.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gradle