{"id":"SUSE-SU-2026:22858-1","summary":"Security update for apache-ivy","details":"This update for apache-ivy fixes the following issue:\n\n- CVE-2026-26032: directory traversal sequences in module coordinates can allow overwriting arbitrary files outside\n  the configured \"buildRoot\" directory (bsc#1271727).\n\nChanges for apache-ivy:\n\n- Upgrade to 2.6.0:\n\n + the ivy:retrieve task failed when the retrieve pattern\n contained some text in parentheses before the first token, for\n instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)\n + when the ivy:deliver task is configured to replace dynamic\n revisions, it now replaces these revisions to the resolved\n revision before any conflict resolution was done, which was\n the original behavior before Ivy 2.3.0. This way, the\n delivered ivy.xml can be used to have reproducible dependency\n resolution, especially when multiple configurations are used.\n It also fixes issues where the dynamic revisions were replaced\n by versions from other configurations. (IVY-1485, IVY-1661)\n + the ivy:deliver task didn't replace dynamic revision from\n inherited dependencies. (IVY-1410)\n + the ivy:install task didn't take the from resolver into\n account when resolving Maven parent modules or\n source/javadoc artifacts.\n + the ivy:checkdepsupdate task could suggest a lesser version as\n update. (IVY-1665)\n + the ivy:makepom task no longer adds a dependency to the\n dependencyManagement section. (IVY-1667)\n + the ivy:deliver task didn't include XML namespaces from a\n parent ivy module when merging the descriptors. (IVY-1658)\n + the ivy:checkdepsupdate task no longer shows evicted versions.\n (IVY-1662)\n * Improvements\n + use Apache Commons Compress for pack200 handling to avoid\n issues on Java 14 and later. If pack200 is needed, make sure\n to add Apache Commons Compress to your classpath. (IVY-1652)\n + ivy:retrieve and the 'post resolve tasks' now support the\n override child element. (IVY-1664)\n + ivy:makepom will now add override elements of the ivy.xml to\n the dependencyManagement section of the generated pom.\n (IVY-1663)\n + ivy:deliver and ivy:publish now writes inherited dependencies\n first to preserve resolve order (IVY-1656)\n + ModuleRevisionId.encodeToString now returns a deterministic\n string that doesn't rely on a implmentation of HashMap\n * New feature\n + added a new nearest conflict manager, which handles conflicts\n in the same way that Maven does. (IVY-813)\n","modified":"2026-07-28T18:24:10.727256974Z","published":"2026-07-22T17:48:55Z","related":["CVE-2026-26032"],"upstream":["CVE-2026-26032"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622858-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26032"}],"affected":[{"package":{"name":"apache-ivy","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache-ivy&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"apache-ivy-javadoc":"2.6.0-160000.1.1","apache-ivy":"2.6.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22858-1.json"}},{"package":{"name":"apache-ivy","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache-ivy&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"apache-ivy":"2.6.0-160000.1.1","apache-ivy-javadoc":"2.6.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22858-1.json"}}],"schema_version":"1.7.5"}