Visit NES for Google Guava Home Page

Guava Release Notes

Comprehensive release notes and changelog for Guava, including security patches, bug fixes, and feature updates across all supported versions.

2 Patched Vulnerabilities
VEX Statements

Google Guava

31.0.2 (NES) - December 1, 2025

Notes

  • This release originates from the open‑source Guava project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.

Bug Fixes

This release patches the following:

  • CVE-2023-2976: an insecure temporary file creation vulnerability in FileBackedOutputStream allows local users or applications on the same system to access files created in the default Java temporary directory
  • CVE-2020-8908: a vulnerability allows a local attacker to exploit insecure default permissions during temporary directory creation, enabling unauthorized access to data stored in those directories when applications use the vulnerable API without additional safeguards. Full Version: 31.0.1-jre-guava-31.0.2