Visit NES for Google Guava Home Page
Guava Release Notes
Comprehensive release notes and changelog for Guava, including security patches, bug fixes, and feature updates across all supported versions.
2 Patched Vulnerabilities
VEX Statements
Google Guava
31.0.2 (NES) - December 1, 2025
Notes
- This release originates from the open‑source Guava project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
Bug Fixes
This release patches the following:
- CVE-2023-2976: an insecure temporary file creation vulnerability in FileBackedOutputStream allows local users or applications on the same system to access files created in the default Java temporary directory
- CVE-2020-8908: a vulnerability allows a local attacker to exploit insecure default permissions during temporary directory creation, enabling unauthorized access to data stored in those directories when applications use the vulnerable API without additional safeguards.
Full Version:
31.0.1-jre-guava-31.0.2