Alpine: gradle: security update to 8.14.4-r0

high Tenable Cloud Security Plugin ID 441026

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs.
When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and
would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would
continue to the next repository in the list and potentially resolve dependencies from a different
repository. If a Gradle build used an unresolvable host name, Gradle would continue to work as long as all
dependencies could be resolved from another repository. An unresolvable host name could be caused by
allowing a repository's domain name registration to lapse or typo-ing the real domain name. This behavior
could allow an attacker to register a service under the host name used by the build and serve malicious
artifacts. The attack requires the repository to be listed before others in the build configuration.
Gradle has introduced a change in behavior in Gradle 9.3.0 to stop searching other repositories when
encountering these errors. (CVE-2026-22816)

- Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs.
When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and
would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would
continue to the next repository in the list and potentially resolve dependencies from a different
repository. An exception like NoHttpResponseException can indicate transient errors. If the errors persist
after a maximum number of retries, Gradle would continue to the next repository. This behavior could allow
an attacker to disrupt the service of a repository and leverage another repository to serve malicious
artifacts. This attack requires the attacker to have control over a repository after the disrupted
repository. Gradle has introduced a change in behavior in Gradle 9.3.0 to stop searching other
repositories when encountering these errors. (CVE-2026-22865)

Solution

Update the gradle library and its related packages to version 8.14.4-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-22816

https://security.alpinelinux.org/vuln/CVE-2026-22865

Plugin Details

Severity: High

ID: 441026

Version: Revision 1.4

Type: Local

Published: 4/30/2026

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.42

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-22865

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 5.8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/16/2026

Reference Information

CVE: CVE-2026-22816, CVE-2026-22865