Hi @[email protected] <[email protected]>,

Regarding Vulnerability in Dependency:

I would like to report one.

the Logback dependency in guacamole client :
https://raw.githubusercontent.com/apache/guacamole-client/1.6.0/pom.xml

The logback-core:1.3.15 is vulnerable with CVE-2026-1225 & CVE-2025-11226.

Hope this is planned for remediation as part of version 1.6.1


Thanks,
Shubham Gaikwad





On Tue, Apr 28, 2026 at 5:10 PM Nick Couchman <[email protected]> wrote:

> On Tue, Apr 28, 2026 at 7:33 AM Bhat, Anant via user
> <[email protected]> wrote:
> >
> > Dear Sir/Madam,
> >
>
> This is a community mailing list, you're not speaking to a single
> person or support team, you've got the Guacamole community :-).
>
> >
> > The current latest version of guacamole v1.6.0 is using java spring
> framework 5.3.x that has reached End-of-Life. Please let us know when we
> can expect next version of guacamole which has this vulnerability fix.
> >
>
> We are actively working to finalize the 1.6.1 release, which will
> update several of the dependencies. We do not have a release date
> identified.
>
> If you believe you've encountered a security vulnerability introduced
> in Guacamole by this or another dependency, please follow responsible
> reporting practices:
> https://guacamole.apache.org/faq/#security
>
> -Nick
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

Reply via email to