PatchSiren

vaadin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW vaadin CVE published 2026-05-19

CVE-2026-7860

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin. This issue exposes environment variables in build logs when the frontend build process fails with a non-zero status. The build environment may contain credentials as secrets, which can be exposed in clear text in CI logs and archived build artifacts if the frontend build fails.