← Vulnerability feed

Vulnerability record · CVE-2026-22865 · published 16 January 2026

CVE-2026-22865: Gradle download of code without integrity check vulnerability

Gradle · Gradle

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would continue to the next repository in the list and potentially resolve dependencies from a different repository. An exception like NoHttpResponseException can indicate transient errors. If the errors persist after a maximum number of retries, Gradle would continue to the next repository. This behavior could allow an attacker to disrupt the service of a repository and leverage another repository to serve malicious artifacts. This attack requires the attacker to have control over a repository after the disrupted repository. Gradle has introduced a change in behavior in Gradle 9.3.0 to stop searching other repositories when encountering these errors.

8.6 CVSS 4.0 High EPSS 0.16% · top 96.0% CWE-494 · Download of code without integrity checkCWE-829 · Inclusion from untrusted sphere
8.6CVSS 4.0 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would continue to the next repository in the list and potentially resolve dependencies from a different repository. An exception like NoHttpResponseException can indicate transient errors. If the errors persist after a maximum number of retries, Gradle would continue to the next repository. This behavior could allow an attacker to disrupt the service of a repository and leverage another repository to serve malicious artifacts. This attack requires the attacker to have control over a repository after the disrupted repository. Gradle has introduced a change in behavior in Gradle 9.3.0 to stop searching other repositories when encountering these errors.

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22865 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-26053Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…EPSS 0.99%9.8CVE-2019-15052Gradle insufficiently protected credentials vulnerabilityThe HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec…EPSS 2.8%9.8CVE-2016-6199Gradle deserialization of untrusted data vulnerabilityObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.EPSS 4.7%8.6CVE-2026-22816Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.17%8.1CVE-2023-35947Gradle path traversal vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…EPSS 0.53%8.1CVE-2021-41588Gradle deserialization of untrusted data vulnerabilityIn Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…EPSS 0.80%7.8CVE-2021-29428Gradle vulnerabilityIn Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …EPSS 0.53%7.5CVE-2022-23630Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-22865), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.