Gradle 9.8.1
Released October 7, 2026. Gradle 9.8.1 is a patch release over 9.8.0, and Gradle recommends everyone use 9.8.1 instead. Before you hit upgrade, know that this one is mostly about closing security holes, so you should treat it as mandatory rather than optional.
Three High-Rated Vulnerabilities
This release addresses three security advisories that all share a theme: untrusted Java objects getting deserialized before authentication. If you run a build daemon in a shared or CI environment, these matter to you.
- Unauthenticated worker-to-daemon channel deserializes untrusted Java objects (GHSA-mvvg-497x-hmj8).
- Deserialization of untrusted Java objects before authentication in client to daemon communication (GHSA-xwqc-3h47-hg64).
- Failure to disable repositories failing to establish an SSL connection can expose builds to malicious artifacts (GHSA-j5m7-59rp-24f5).
What Else Got Fixed
- Gradle 9.8.0 complained again about invalid Toolchains on Debian and Ubuntu packaged systems; that noise is gone.
- A regression that removed root java.util.logging handlers installed by a custom LogManager (it broke Quarkus test log capture) is resolved.
- A dependency resolution regression is fixed.
The Caveat
None of these are new features. If you were hoping 9.8.1 would add anything shiny, this is a hardening release. Upgrade for the fixes, and update any pipeline entries that pin Gradle 9.8.0.