Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:36012: Important: maven:3.9 security update

  • What: Security update for maven:3.9
  • Impact: Addresses security vulnerabilities in Red Hat Enterprise Linux
Read Full Article →

Red Hat Product Errata RHSA-2026:36012 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:36012 - Security Advisory Overview Updated Packages Synopsis Important: maven:3.9 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the maven:3.9 module is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2451409 - CVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method CVEs CVE-2025-67030 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM aopalliance-1.0-51.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: b2c8dcc3b0e4315866c81c0e05a6cdebc861c428fb6fab68d8b32d4e4a7c3201 apache-commons-cli-1.9.0-4.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: a509a5462f487f35e24c041430323da1045a4863ecfa57ffec1c8e99a4c3cb1a apache-commons-codec-1.17.1-8.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: c17f694ad78ac4d20f94444971c4cc35f8d9a165c68cd2c7c6160344e93505ad apache-commons-io-2.16.1-9.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 2cd4b532b9af01c5d7276c271d446052f4413ef0fe752db7e34c9f13e705aaba atinject-1.0.5-14.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 9f5c211c30324ca876b16ea9cdb540c0f86ba16157fbe587e17ec504f87d87e7 google-guice-5.1.0-23.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: acd1b9ed12d038dc36983600c75411c8b7146751af05db74fbe2f0bf0603c9ec guava-33.3.0-5.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: f03e12c95aa207ff657d76d2aa9c0b531d5a764f292b06efce6083957d71bc43 httpcomponents-client-4.5.14-21.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: e7e5c1e237010b3e3e43e96e62f626631396edae75764a3ec131752c28f4e599 httpcomponents-core-4.4.16-21.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 27dc292c2bfc3558b3447f06e1c8da6bb0653f0125c2718c1ceba1768153d05a jakarta-annotations-1.3.5-38.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 18af9a208bfc59092427c322d26e6cafad8851cbe57a43013bf6509bc301ef41 jansi-2.4.1-12.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: c238f10ba40968ae2de0d49ecee3afe7f9f623123f6323a840b0dd8cf4241362 jsr-305-3.0.2-36.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 54cc80ca3a86b71a7d819df217565df86e47465959e1c1b3bda8ff8425525d20 maven-3.9.9-12.module+el9.6.0+24382+3f72e30c.src.rpm SHA-256: 995191f416960a274666d3d3c0f766ecd9e5af890d4d9597f3d44a3e68eb1861 maven-resolver-1.9.22-6.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: c051eccb178ab9c43f191b9a9b25af4a641de7e9204e1cdad6c3290ee8c11763 maven-shared-utils-3.4.2-19.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 9d0d6d6155cf519b995ac69b2c56a52523e77c3dd057f89e4fe6127e0ee44454 maven-wagon-3.5.3-17.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 9982da04ffafe062c0d132b3ed792bce71048002eedfb83c9063998083515c0a plexus-cipher-2.0-25.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 8eac1167ff1500aec2665b3bd382b0da4200229043dc02bebac0cf0e02de393e plexus-classworlds-2.8.0-9.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: cb104ff8887a3e24987e7a3afc1d4a86c6837978caabf2887d8b118e9bf6a148 plexus-containers-2.2.0-10.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 32a3ffc3b19d1b8fb463250a302cf4cd150703c811073fec53dd3789c17a2da0 plexus-interpolation-1.27-10.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 7cc06c33f53d7456db1de254a3e6cbdbafa2605d97b5851ca06248b7c9235c16 plexus-sec-dispatcher-2.0-28.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 27ee27b60d7cf50f5046ab8242d26ac04de890e77387af3d04241260e5998ee3 plexus-utils-3.5.1-17.module+el9.6.0+24382+3f72e30c.1.src.rpm SHA-256: b3c999bc2da35f59ca9a28adec4b4f9bec8b95e2a2b70922f42adb6cbbfcb09e sisu-0.9.0~M3-7.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: d78caf7409a91931e4a09a26cef854cc492fb2ff2c636f17547d14ee45faf8dc slf4j-1.7.36-9.module+el9.6.0+22733+e520f63c.src.rpm SHA-256: 60743ae124ca0ab91e119dc8691dbca5db8c21bbe06ff606e1b4d08f28a91425 x86_64 aopalliance-1.0-51.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 4986e396090605671bf9fb6b59bbac39edfb38eae9eb0bb4c7f4f78aebce2bbe apache-commons-cli-1.9.0-4.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: b45a08a4d7bfef883c96c57a216eaa6e71014247d1d4bcfd0a42abf0789b6a17 apache-commons-codec-1.17.1-8.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 00f127d6c8dbbd589e411503a9831398b8dd65eb6abfc619eb8f80ea47705cbd apache-commons-io-2.16.1-9.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: f0607a864ca4f419a7f2ae6342edeb91756b059e9dd07bba79b5d867c7b3165b atinject-1.0.5-14.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: f324858800e24cc4bc664a0656ee4bb91a03ed68332ac1a6642bd5a4dfdb3d84 google-guice-5.1.0-23.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 1dccc69ae8309cd8a2f2f7c8053b3bcbf9fa1eea1518e18803b837b31e71b2f0 guava-33.3.0-5.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 73ad05c5436b0ff84f8ce6f7e35d0d0ecbb055993dd444a2c4108dca526223b5 httpcomponents-client-4.5.14-21.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 8f782a2ba0225a1e9deb1654e0815269a73d1c1632852f7fffa5a60e83afafa6 httpcomponents-core-4.4.16-21.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 2c248e3cf95c8e237f381fde94fd5c62cef34503a44d1d239d459b42f3309dff jakarta-annotations-1.3.5-38.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 17e7a456091dc0d77b9cebfdd0206b31bceda495a99a4bfd28c3793b7f3f798b jcl-over-slf4j-1.7.36-9.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 6bf66f3e41770976dad52e4f0150aea4a2a584c2989c626c5896b2b139b3c654 jsr-305-3.0.2-36.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: e87b966e780378cd347db9f32d1f782e8f19ee7d9f8a3e563c0208fa86d564c3 maven-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: 7baa4555ef6402780914a030b505552481a49106ba171fe57293be2cb8de9c75 maven-lib-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: 539249009c44b65a54a3cb1478b0e54817a67f0d1e0ac0a70e314359fd03fae1 maven-openjdk11-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: 094331a77a4a8108b380c5a8853d6359c1d81b94e7ae761d6fbd8517eaf89255 maven-openjdk17-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: b9acf0d32a69c941ab5183abe1f4c7f70d1989b298ce1aeb589c53b9a9881a9b maven-openjdk21-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: f4ff1e61a21e9aca917813b7d1f258394ba09b16b2309c617a372d970328dc88 maven-openjdk8-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: 3d3b0486cb5ebd0a81bd3979f8ad4f81eca4d7b77b32f90647f495fef9d8e1b4 maven-resolver-1.9.22-6.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: bf720b276ea8d172adad8dfa24761bd4415114f626ed12ff8e72757ef04d52d4 maven-shared-utils-3.4.2-19.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: ae3b80cf9109401c70e806a5afe11a15a0cd30114aae492566ce736ffd7b72ec maven-unbound-3.9.9-12.module+el9.6.0+24382+3f72e30c.noarch.rpm SHA-256: 0938227f79bff30fed7a6ba067b40e20ceaa5938dbdb42786a701024b18fe5f1 maven-wagon-3.5.3-17.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: df33bcabfecc032d66d54f5b3b4738a9f8cd91d0e3e96c0bcd2814b23863b888 plexus-cipher-2.0-25.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 2600ae99794da93ac7fd2c7ef3f86cff2946d7c662946c561e5cc480a99db0e9 plexus-classworlds-2.8.0-9.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: d488599cb50c24bebd504912739ed9371f0efbfa36f71a548a0ff2b8cede96ad plexus-containers-component-annotations-2.2.0-10.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: ccf6fcdc6e19c1d136fb9c55187c9db45b459acf0390c04c30ee68e4257725eb plexus-interpolation-1.27-10.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 6eb5b4b9406065b880098f1e01a405c223d48543d26f1c00957f8acfa0b6a046 plexus-sec-dispatcher-2.0-28.module+el9.6.0+22733+e520f63c.noarch.rpm SHA-256: 0efff320bfc22193a6a03c733f37f55aa5f99b5df0584a3f4df02810a80eb5c4 plexus-utils-3.5.1-17.module+el9.6.0+24382+3f72e30c.1.noarch.rpm SHA-256: c6408e0de4d181d589ef77ffef60cb07c38513a0dfa389123

Share this article