PT-2026-3330 · Gradle · Gradle

Ljacomet

·

Published

2026-01-16

·

Updated

2026-01-22

·

CVE-2026-22816

CVSS v4.0

8.6

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Gradle versions prior to 9.3.0
Description Gradle’s native-platform tool, which provides Java bindings for native APIs, does not treat certain exceptions as fatal errors when resolving dependencies in versions before 9.3.0. This allows Gradle to continue to the next repository, potentially resolving dependencies from a different source. Specifically, an unresolvable host name does not halt the process, allowing an attacker to register a service under the build’s host name and serve malicious artifacts if the malicious repository is listed before others in the build configuration.
Recommendations Update to Gradle version 9.3.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-GRADLE-2026-22816
CVE-2026-22816
GHSA-W78C-W6VF-RW82

Affected Products

Gradle