Hi @[email protected] <[email protected]>, Regarding Vulnerability in Dependency:
I would like to report one. the Logback dependency in guacamole client : https://raw.githubusercontent.com/apache/guacamole-client/1.6.0/pom.xml The logback-core:1.3.15 is vulnerable with CVE-2026-1225 & CVE-2025-11226. Hope this is planned for remediation as part of version 1.6.1 Thanks, Shubham Gaikwad On Tue, Apr 28, 2026 at 5:10 PM Nick Couchman <[email protected]> wrote: > On Tue, Apr 28, 2026 at 7:33 AM Bhat, Anant via user > <[email protected]> wrote: > > > > Dear Sir/Madam, > > > > This is a community mailing list, you're not speaking to a single > person or support team, you've got the Guacamole community :-). > > > > > The current latest version of guacamole v1.6.0 is using java spring > framework 5.3.x that has reached End-of-Life. Please let us know when we > can expect next version of guacamole which has this vulnerability fix. > > > > We are actively working to finalize the 1.6.1 release, which will > update several of the dependencies. We do not have a release date > identified. > > If you believe you've encountered a security vulnerability introduced > in Guacamole by this or another dependency, please follow responsible > reporting practices: > https://guacamole.apache.org/faq/#security > > -Nick > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > >
