#1147425 ant: CVE-2026-78254

Package:
src:ant
Source:
src:ant
Submitter:
Moritz Mühlenhoff
Date:
2026-09-13 04:07:03 UTC
Severity:
normal
Tags:
#1147425#5
Date:
2026-09-11 17:03:17 UTC
From:
To:
Hi,

The following vulnerability was published for ant.

CVE-2026-78254[0]:
| The ftp and scp tasks of Apache Ant can download files from a remote
| server. A malicious server can provide relative paths that allow it
| to write outside of the dedicated target directory for the download,
| making it possible to overwrite files of the attacker's choice using
| the permissions of the user running Ant in versions prior to Ant
| 1.10.18.      In order to exploit this vulnerability, the server
| would either have to be malicious or be subject to a machine-in-the-
| middle attack. Additionally in the case of scp or the ftp task using
| ftps the server must pass the server identity checks performed by
| the tasks.     For ftp tasks not using ftps a malicious server could
| act as a machine-in-the-middle to provide malicious files.
| Starting with Ant 1.10.18 both tasks will prevent writing outside of
| the destination directory by default. An option is available to
| disable this behavior in the unlikely case that the  old behavior is
| required by existing build files.     Mitigations:     Users of scp
| and ftp (when using ftps) in any version of Ant should not bypass
| server identity checks. Users of ftp not using ftps should switch to
| ftps where possible.     All users are recommended to upgrade to
| Apache Ant 1.10.18, which fixes this issue.

https://www.openwall.com/lists/oss-security/2026/09/06/2

https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2 (ANT_1.10.18_RC1)
https://github.com/apache/ant/commit/9252566cab812c59a5695679ba11f497e85aabb0 (ANT_1.10.18_RC1)
https://github.com/apache/ant/commit/3807d672ea18d9f8dafd5eb9b2fe1de05f664539 (ANT_1.10.18_RC1)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78254
https://www.cve.org/CVERecord?id=CVE-2026-78254

Please adjust the affected versions in the BTS as needed.

#1147425#12
Date:
2026-09-13 04:04:42 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
ant, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147425@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
tony mancill <tmancill@debian.org> (supplier of updated ant package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 15:20:27 -0700
Source: ant
Architecture: source
Version: 1.10.18-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: tony mancill <tmancill@debian.org>
Closes: 1147425
Changes:
 ant (1.10.18-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release
     Addresses CVE-2026-78254 (Closes: #1147425)
   * Dropped patches applied upstream:
     - 0009-reproducible-timestamp-task.patch
     - 0011-reproducible-propertyfile-task.patch
Checksums-Sha1:
 03cd579d6fbb9e9bfe5e5f1721b53a8559efab53 2436 ant_1.10.18-1.dsc
 1d71b7e8ea91b464f73e890f7514b8be0e15c0a2 3402152 ant_1.10.18.orig.tar.xz
 7aa23adccb0fd751cd2cba07c36743db7d2a9737 19636 ant_1.10.18-1.debian.tar.xz
 ec438d64eeb426677b362ce13bb1e286f58f1a3c 12224 ant_1.10.18-1_amd64.buildinfo
Checksums-Sha256:
 a5c3e254ca7a312734c3750d902e4399922b95cdd0649727e2232dc8a8bf056f 2436 ant_1.10.18-1.dsc
 1b81acba4df4244e4d85f923a9edf7f0dd9e8421ac7f8e3dd598d10893ba1497 3402152 ant_1.10.18.orig.tar.xz
 41a3025e44eeac65a1ac15af88bcc8658655a05bc9978663939621117738611e 19636 ant_1.10.18-1.debian.tar.xz
 a4afb7c881f68bfb104a4d3bc9be497e9f5be54981286961d9ea6281e0946568 12224 ant_1.10.18-1_amd64.buildinfo
Files:
 c2b3cebfed347ed3637bc0d6325860bf 2436 java optional ant_1.10.18-1.dsc
 bd457f76381e7381014162d4bc80e629 3402152 java optional ant_1.10.18.orig.tar.xz
 d3bee150f90a841d6217eb94b636d7ea 19636 java optional ant_1.10.18-1.debian.tar.xz
 538b4fa469a12fb3d13a23995db9a98a 12224 java optional ant_1.10.18-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEE5Qr9Va3SequXFjqLIdIFiZdLPpYFAmqmHZUUHHRtYW5jaWxs
QGRlYmlhbi5vcmcACgkQIdIFiZdLPpaWYg//aovDxh4VsNVYvEZwAMTjlDTCGtGS
IKSRSFeJZtLQdtOi2V33GXcOslBFvx79PGiF+bKAOKOV8UN6DWp/mOQ5iurF2ABX
O/7dTMM3pUOWEtb05bQ9LwcPLFFrtTAbWlTAj3hsAdpwbkCVJlONopoP3r7Ak1gM
99WR+l59AE9KRvXBqHT8uRLlnVyfu9UgAANg5I8W0YAEJf8nDnE6wt23UWexJMns
kjMRjHkGoBnOM6wA7JKAOiMwJNVpTa2/SQTYSV0bc8BtKQLlae/UqlirmKxQSGU5
wQMYUw0BzPsB5CdrUZEIo3ojWiB865hyPN65i1PDKkxHQGn1S6N+4QQxG+pdQd6w
GiQoyTY5PxfnREuM2hOLGZIMz472VV3y40CCXS1X2ZMFxZOnBPSyrV0JpPSza6mc
rryUoF5K2cSKbuOdpIXnQLByc1jQjcIwIetcFvBqbW9zfb++UQsypI2DVEKb4a5G
Ls9jQKiWfrCW+Awg9LnssmaT3tdWk+X25cp9kGN612K3S87ZCwCD5XmCRWvuNPuR
IsyHIDLTgf3M6dk+xVRgp2aY4dTG6XFBL23bJgPGVinVwDiMRjdl0d3iKXGWifLh
94xIaogZyEtGa4hXbBsu4zxEAsCGeb/tLmqj23eTCa4VyOkPojflLu0yfGgQn0zx
tHqrMR70Qjjl5js=
=BxoP
-----END PGP SIGNATURE-----