Red Hat Product Errata RHSA-2026:35996 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35996 - Security Advisory Overview Updated Packages Synopsis Important: maven:3.8 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the maven:3.8 module is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2451409 - CVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method CVEs CVE-2025-67030 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM apache-commons-cli-1.5.0-4.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: b58d4f20c24c8cc17ed4ebab997dcbc8f15add2906dd8f3f63ec381e10bfc4e2 apache-commons-codec-1.15-7.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: db3db7ae6f3fea29293949de0cc20a704ec6824834761e29446408ce3407282f apache-commons-io-2.11.0-2.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: a49848baf6d0e89c3d9f6b85ff0911db9c2a19407da07fd64c8d4d05d80af9d0 apache-commons-lang3-3.12.0-7.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: b330e626b0d582f1c1b8352344afa05465494175fbbcc2f570899b101ddfa70c atinject-1.0.5-4.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 16772ad72fdc2bd5d409ff9051d49a012f3ebd834b4a0ba774a9fbb1e67a826d cdi-api-2.0.2-6.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 952e318c80a67f6478b89c5db83c4f3fc60dd276f0a62f8f11104a78b433aeea google-guice-4.2.3-9.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 90284394ce780ea925412078e04b59d18f2cd933deb27db3d2331c305b63ffed guava-31.0.1-4.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: caa6704edaf4f1098e36e40c687c9cc135e8e8a45948664f43fca2d2a86338fc httpcomponents-client-4.5.13-5.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 99971f8e39817f09b5f0bb9b928283364da272fb13686315ec8e2c830ebfc06a httpcomponents-core-4.4.13-7.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 1d6d799abc0b76f6884a123c87cccbded0d0b697deea1e75838000f77db264d7 jakarta-annotations-1.3.5-14.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 923bdb8855266bc92a66dd44c8e7c81d7fd583c35b4d3ac573a8313f3aa61e91 jansi-2.4.0-6.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: eda7bdf61e6138ebc8e2119e189594f754b4e78e491e57654997ed3fcce27598 jsr-305-3.0.2-6.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: cc76f3c779db811e85573401e7556df2face0311ade75f2a62af35cfa92b8bd4 maven-3.8.5-4.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 7295526f707df0f85415ad9f454f9d768787622190ac36bf2ee08932e895b826 maven-resolver-1.7.3-5.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 4657c4a554e3598ef1d4dcae5818ec54d9dc221b501ddec0330fc657502a808f maven-shared-utils-3.3.4-5.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 5dc24236d2f8e48f5fade43614cd5da6b98366aaab5205678a769721daeb1aba maven-wagon-3.5.1-2.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 8dfcbb6ef8866d1aaa137f0ec7105ddfbfab670cd6c9dcac9475d285fc54f58a plexus-cipher-2.0-2.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: cc1fe66e2f4d5dd0a9aee4f431792740b45763e28e18c8d896c8c4577d4acca9 plexus-classworlds-2.6.0-12.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 9dfcfafd17e8fd663c7aa9275be8c29780e5c983790e903f6fccb5129957c7a3 plexus-containers-2.1.1-2.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: cd770608194f41a7a5d6cb6b44e82d0dd57de7bc1f9bdf82c5e0064043f07d9a plexus-interpolation-1.26-12.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: a6e48d1ba4d89407524c2a62913d95ab3c4b0ac4a3b40d3b9be685e6e84c02fc plexus-sec-dispatcher-2.0-4.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 0b1406f4fe25cab3362a6c9b6b4beb243e2fddb6aa6f1249ed4a363a85e2f38e plexus-utils-3.3.0-10.module+el8.8.0+24386+48baf958.1.src.rpm SHA-256: 84ad8485116159274f7ec9e2700706077d6c60179b79db8d994166676cdeb127 sisu-0.3.5-2.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: dc8e6e6643f35ff9931993602dbe70654ce15aa241e1e94c863c7b2f2673ff1b slf4j-1.7.32-4.module+el8.8.0+18044+0a924b8f.src.rpm SHA-256: 9d01b30abcdb6d440f46efdb22f8e2ef382d42f2584b993ba751ca3042abe79f x86_64 apache-commons-cli-1.5.0-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 7ca1ded81dae0c4148774e6f4e965a93fc5fb81715aec5b6d34b9c10b7ff9f08 apache-commons-codec-1.15-7.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 0fe6731005682c3698b0e2b886363aa6a43926d431af4986f13b56227dac3b1c apache-commons-io-2.11.0-2.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 98161222109cdff20fdeeced802bac4f60228f054a3162f2600c8a89d932bfbf apache-commons-lang3-3.12.0-7.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: a7023d039d9538be1fdd3a6b93a0827a34d3cc73b5c7684c4da625cf9ec1ada2 atinject-1.0.5-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 2adaad7947ac929f2e4f91613df09e9daeea1f7a75bc1ead5fe22d1c8196677f cdi-api-2.0.2-6.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 5fc5204d73d0483e0017a61ca01c2ce5abd462e77f8ba281d65595e34b089dc7 google-guice-4.2.3-9.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 98ab4f0b995f408097d28b28cad28fb131a854db1a690e782444fa9e976d396d guava-31.0.1-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 7bae0de69d2451750ddfc709ea6cec905f463fba8232615e6820209bf57d0e41 httpcomponents-client-4.5.13-5.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: f3dbf0db4b1025382cb093b9ecbc9b5dba38d4353bf3ad95d8304b1e0864f76c httpcomponents-core-4.4.13-7.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 380cc5498dc984f19460907c94eb19531ca5d8e40e735d98e1a289588132e8ba jakarta-annotations-1.3.5-14.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: f16dfddbf6350845c6a96919bbc70ade211a7b572852843ac16ef88612a6adf7 jcl-over-slf4j-1.7.32-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: d9618ed3e72d9085d413bc985d3b10ad44c7d25b3b9f271e23db3f95bee13c0d jsr-305-3.0.2-6.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 11bb9b62c3d9230be3092346ebfad8537e5d650bf1cf87ce9e26f32ecee707dc maven-3.8.5-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 96296f1551ff62d1deac8daaed90048bdaf29dea1f9b00cab1272226a814bcc6 maven-lib-3.8.5-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 3cabc4f7710f4d9e755bb1a1bb4866d4b546bc55a7fd9fbc38fecbdd140796f7 maven-openjdk11-3.8.5-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: fb6aeac0fa01eb6cfac038c1dc36fbb2b93f09248dc1af9a70364cf4d1466013 maven-openjdk17-3.8.5-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: a2dcbd2e7cc31d08903004973b7c5661ef2a6c386a21ade096c5eb92fc22ab5c maven-openjdk8-3.8.5-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: df4f4cf5683b5fb5a31e2d10d3572eefd41c11c2afa4a2e5179df3dce9b39b02 maven-resolver-1.7.3-5.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 1e9adaf716d7b4c28c9c3a6cc79144e6752f1059fd91e77452a2e54644f63031 maven-shared-utils-3.3.4-5.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: b89ee0d6db370f8ba6b3d9eaded5f64880a5978cdda374e51c6991d72a9008de maven-wagon-3.5.1-2.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 08eb7f84304dc2015b2718212abdd5d90b30d5aefc64d72258c07c835409e924 plexus-cipher-2.0-2.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: faf1c294c62a5a1fd3abc98bfe2930716c2cd61033a55ec2587b8b23a7f61f94 plexus-classworlds-2.6.0-12.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 6378d7b151e9fc9cc8f13080a3b1d83567ff336f2372f4e02172631379fe705e plexus-containers-component-annotations-2.1.1-2.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 1db43b5c96e795c9d13b1c934b0e01cdd81611a55ebb0d78cc5edfce686658a4 plexus-interpolation-1.26-12.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: a4ecf131fdc4ccb1c546cac298f52dce63bfe5a1f20d353b47167c0e742ae0a0 plexus-sec-dispatcher-2.0-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 37bd841715b9250d0082d0aef0de09401a41b5c7c606b5e511bf6fdf8e7777ed plexus-utils-3.3.0-10.module+el8.8.0+24386+48baf958.1.noarch.rpm SHA-256: 811b51fbc6e65ccd3b801af45638d88c7d91d8e15a9af8151366539a066116ba sisu-0.3.5-2.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: ca4a3b65030025a6839f29f38e23f786fe48d0144f3d8736acbcb6f978f5dd2b slf4j-1.7.32-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 0386724de32c13176ec836b7d3463eaf093b8f65efb11261efde16a8178f2caf apache-commons-cli-1.5.0-4.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 7ca1ded81dae0c4148774e6f4e965a93fc5fb81715aec5b6d34b9c10b7ff9f08 apache-commons-codec-1.15-7.module+el8.8.0+18044+0a924b8f.noarch.rpm SHA-256: 0fe6731005682c3698b0e2b886363aa6a43926d431af4986f13b56227dac3b1c apache-commons-io-2.11.0-2.module+el8.8.0+18044+0a924b8f.
A directory traversal vulnerability (CVE-2025-67030, CVSS 8.8 High) in the `extractFile` method of `org.codehaus.plexus:plexus-utils` allows for path manipulation during archive extraction. Affected versions are plexus-utils prior to 3.6.1 and versions 4.0.0 through 4.0.2. The fix requires upgrading to plexus-utils version 3.6.1 or 4.0.3, which is included in the provided Red Hat security update for the maven:3.8 module.