Skip to main content
Question

Rundeck Vulnerability reported - CVE-2026-22732

  • May 5, 2026
  • 4 replies
  • 227 views

Forum|alt.badge.img

Hi all, quick vulnerability question.

Our vulnerability software has flagged up Rundeck v5.20 with CVE-2026-22732 because of the component spring-security-web-5.8.15.jarΒ 

I could not find anything about this CVE in this forum or Rundeck web page.

How can we find out if there’s a fix for this coming up soon?

Is there a place to report this?

Thanks!

4 replies

Forum|alt.badge.img
  • PagerDuty Team πŸ“Ÿ
  • May 5, 2026

Hi ​@Carlos.AΒ Β I've reported this to the engineering team. Thanks a lot for your feedback!Β 


Forum|alt.badge.img
  • Author
  • New Member πŸ‘‹
  • May 7, 2026

Really appreciate it ​@MegaDrive68kΒ 

Does PagerDuty have an SLA for remediating critical CVEs?

Our Security department is pretty strict, and it’s mandatory for us to remediate CVEs on our live systems.

Β 

Thanks again, Carlos


Forum|alt.badge.img
  • Author
  • New Member πŸ‘‹
  • June 1, 2026

Hi,Β 

Any luck with this?

Anything I can report back to our cybersecurity department?

Β 

thanks

Carlos


Forum|alt.badge.img
  • PagerDuty Team πŸ“Ÿ
  • June 2, 2026

Hi Carlos, sorry for the delayed response. That fix should be available in Rundeck 6.0 (the next major release). The component has been updated to the fixed version (see gradle.properties), addressing the vulnerability detailed in CVE-2026-22732.

Right now, we don't have a specific ETA for Rundeck 6.0, but it is very close to being released. You can track its progress on the GitHub milestone page here: https://github.com/rundeck/rundeck/milestone/248.