{"id":"CGA-h8hc-g3pw-2jph","modified":"2026-09-08T18:27:36.830615354Z","published":"2026-09-07T14:27:56Z","upstream":["CVE-2016-6199","GHSA-f65r-2xfr-g5gx"],"references":[{"type":"ADVISORY","url":"https://philwantsfish.github.io/security/java-deserialization-github"},{"type":"EVIDENCE","url":"https://discuss.gradle.org/t/a-security-issue-about-gradle-rce/17726"}],"affected":[{"package":{"name":"eco-java-gradle-2.12","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/eco-java-gradle-2.12?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_name":"eco-java-gradle-2.12","component_version":"2.12-r1","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/eco-java-gradle-2.12@2.12-r1","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-09-07T14:28:51Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-h8hc-g3pw-2jph.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}