GHSA-c9q6-g3hr-8gww

Suggest an improvement
Source
https://github.com/advisories/GHSA-c9q6-g3hr-8gww
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-c9q6-g3hr-8gww/GHSA-c9q6-g3hr-8gww.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c9q6-g3hr-8gww
Aliases
Published
2026-01-13T14:55:35Z
Modified
2026-02-03T03:11:38Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Jervis Has Weak Random for Timing Attack Mitigation
Details

Vulnerability

https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L593-L594

Uses java.util.Random() which is not cryptographically secure.

Impact

If an attacker can predict the random delays, they may still be able to perform timing attacks.

Patches

Jervis will use SecureRandom for timing randomization.

Upgrade to Jervis 2.2.

Workarounds

None

References

Database specific
{
    "cwe_ids":  [
        "CWE-330"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-13T14:55:35Z",
    "nvd_published_at":  "2026-01-13T20:16:07Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / net.gleske:jervis

Package

Name
net.gleske:jervis
View open source insights on deps.dev
Purl
pkg:maven/net.gleske/jervis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2

Affected versions

0.*
0.1
0.2
0.3
0.4
0.5
0.5.1
0.5.2
0.6
0.7
0.8
0.9
0.10
0.11
0.12
0.13
1.*
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
2.*
2.0
2.0.1
2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-c9q6-g3hr-8gww/GHSA-c9q6-g3hr-8gww.json"