On Tue, May 19, 2026 at 1:47 AM Shubham Gaikwad <[email protected]> wrote: > > Hi @[email protected], > > Regarding Vulnerability in Dependency: > > I would like to report one. > > the Logback dependency in guacamole client : > https://raw.githubusercontent.com/apache/guacamole-client/1.6.0/pom.xml > > The logback-core:1.3.15 is vulnerable with CVE-2026-1225 & CVE-2025-11226. >
Shubham, 1) As has already been mentioned, we will deal with dependencies during release time. 2) I also asked in the e-mail that you replied to that security issues be responsibly and privately to the security@ mailing list. Even if the vulnerability exists in a dependency, depending on the nature and severity of it there may be serious implications for Guacamole. Please follow this guidance. -Nick --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
