← Vulnerability feed

Vulnerability record · CVE-2021-41588 · published 24 September 2021

CVE-2021-41588: Gradle deserialization of untrusted data vulnerability

Gradle · Gradle

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

8.1 CVSS 3.1 High EPSS 0.80% · top 45.3% CWE-502 · Deserialization of untrusted data
8.1CVSS 3.1 base score, v2 6.8
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41588 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-26053Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…EPSS 0.99%9.8CVE-2019-15052Gradle insufficiently protected credentials vulnerabilityThe HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec…EPSS 2.8%9.8CVE-2016-6199Gradle deserialization of untrusted data vulnerabilityObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.EPSS 4.7%8.6CVE-2026-22816Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.17%8.6CVE-2026-22865Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.16%8.1CVE-2023-35947Gradle path traversal vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…EPSS 0.53%7.8CVE-2021-29428Gradle vulnerabilityIn Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …EPSS 0.53%7.5CVE-2022-23630Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2021-41588), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.