{"id":"CGA-qpp4-983f-rc73","modified":"2026-09-07T22:03:53.394603749Z","published":"2026-09-07T15:54:27Z","upstream":["CVE-2018-1324","GHSA-h436-432x-8fvx"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd%40%3Cdev.creadur.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r5532dc8d5456b5151e8c286801e2e5769f5c04118b29c3b5d13ea387%40%3Cissues.beam.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/1c7b6df6d1c5c8583518a0afa017782924918e4d6acfaf23ed5b2089%40%3Cdev.commons.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/103490"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1040549"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"}],"affected":[{"package":{"name":"eco-java-gradle-4.8.1","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/eco-java-gradle-4.8.1?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:maven/commons-compress@1.14","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-09-07T15:54:31Z","component_name":"commons-compress","component_version":"1.14","component_type":"java-archive","component_location":"/usr/lib/gradle/4.8.1/lib/commons-compress-1.14.jar"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-qpp4-983f-rc73.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}