{
  "published": "2026-09-07T13:40:57Z",
  "modified": "2026-09-07T13:41:38Z",
  "schema_version": "1.7.5",
  "id": "CGA-4f26-4pg4-2xm7",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    }
  ],
  "upstream": [
    "CVE-2016-6814",
    "GHSA-xphj-m9cc-8fmq"
  ],
  "references": [
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujul2020.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://rhn.redhat.com/errata/RHSA-2017-0272.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securityfocus.com/bid/95429"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securitytracker.com/id/1039600"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2017:0868"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2017:2486"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2017:2596"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.gentoo.org/glsa/202003-01"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
    },
    {
      "type": "FIX",
      "url": "http://mail-archives.apache.org/mod_mbox/www-announce/201701.mbox/%3CCADRx3PMZ2hBCGDTY35zYXFGaDnjAs0tc5-upaVs6QN2sYUejyA%40mail.gmail.com%3E"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Chainguard",
        "name": "eco-java-gradle-2.4",
        "purl": "pkg:apk/chainguard/eco-java-gradle-2.4?arch=x86_64"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "components": [
          {
            "component_name": "groovy-all",
            "component_version": "2.3.10",
            "component_type": "java-archive",
            "component_location": "/usr/lib/gradle/2.4/lib/groovy-all-2.3.10.jar",
            "component_purl": "pkg:maven/groovy-all@2.3.10",
            "latest_event_status": "pending_upstream_fix",
            "latest_event_timestamp": "2026-09-07T13:41:38Z"
          }
        ]
      }
    }
  ]
}
