GHSA-xphj-m9cc-8fmq · Severity: critical · Ecosystem: maven — Deserialization of Untrusted Data in Groovy
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.
Conclusion & alert: CVE-2016-6814 is rated High Risk (68.1/100): CVSS Critical severity, with high exploitation likelihood (EPSS 17.55%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 24.32% | 17.55% | -6.77% |
| 2 | 2026-04-24 | 25.71% | 24.32% | -1.40% |
| 3 | 2026-03-04 | — | 25.71% | — |
Full EPSS history (42 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-xphj-m9cc-8fmq · Severity: critical · Ecosystem: maven — Deserialization of Untrusted Data in Groovy
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2016-6814 not yet assigned priority: Debian including 1 source packages (groovy), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-6814 |
gentoo
|
normal | CVE-2016-6814: 1 GLSA(s) (202003-01), 1 atom(s) (dev-java/groovy); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2016-6814 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2016-6814 |
ubuntu
|
medium | CVE-2016-6814 medium priority: Ubuntu including 2 source packages (groovy, groovy2), 46 status rows across 23 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, xenial, yakkety, zesty): DNE 22, not-affected 18, ignored 2, released 2, needed 1, needs-triage 1. | https://ubuntu.com/security/CVE-2016-6814 |