Gradle is a widely adopted build-automation and dependency-management platform embedded across development toolchains and CI/CD pipelines, where its plugins and caching layers integrate with projects at the compilation and artifact-resolution stage. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the exposure spans both the core build tool and its enterprise-grade caching and server products. The recurring weakness classes—untrusted deserialization, credential exposure, path traversal, and inclusion of functionality from untrusted sources—reflect the inherent risks of build systems that must resolve and execute third-party dependencies and manage authentication across distributed networks. Defenders should treat Gradle advisories as relevant to entire development pipelines and supply chains, since a compromised build tool or misconfigured cache can propagate to downstream artifacts; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gradle over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27919CRITICAL Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous a | Mar 25, 2022 | 9.8 | 32 | NO | NO |
CVE-2016-6199CRITICAL ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object. | Feb 7, 2017 | 9.8 | 31 | NO | NO |
CVE-2021-41589CRITICAL In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node wit | Oct 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-26053CRITICAL Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependenc | Mar 2, 2023 | 9.8 | 29 | NO | NO |
CVE-2019-15052CRITICAL The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those cred | Aug 14, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11403CRITICAL In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page. | Apr 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11402CRITICAL In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format. | Apr 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2020-15776HIGH An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the abil | Sep 18, 2020 | 8.8 | 28 | NO | NO |
CVE-2025-24858HIGH Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash | Jan 26, 2025 | 8.3 | 27 | NO | NO |
CVE-2023-49238CRITICAL In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system us | Jan 9, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gradle.
Media articles that mention a CVE ID that affects a product developed by Gradle — matched by CVE ID, not by vendor name.