On Tue, May 19, 2026 at 1:47 AM Shubham Gaikwad
<[email protected]> wrote:
>
> Hi @[email protected],
>
> Regarding Vulnerability in Dependency:
>
> I would like to report one.
>
> the Logback dependency in guacamole client : 
> https://raw.githubusercontent.com/apache/guacamole-client/1.6.0/pom.xml
>
> The logback-core:1.3.15 is vulnerable with CVE-2026-1225 & CVE-2025-11226.
>

Shubham,

1) As has already been mentioned, we will deal with dependencies
during release time.
2) I also asked in the e-mail that you replied to that security issues
be responsibly and privately to the security@ mailing list. Even if
the vulnerability exists in a dependency, depending on the nature and
severity of it there may be serious implications for Guacamole.

Please follow this guidance.

-Nick

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to