Network Vulnerability in Oracle Java SE and GraalVM Products
CVE-2025-50106
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 15 July 2025
What is CVE-2025-50106?
A vulnerability exists in Oracle Java SE and GraalVM products that allows an unauthenticated attacker with network access to exploit the system. This vulnerability can be triggered through multiple protocols, potentially leading to the takeover of affected Java deployments. The flaw is related to the way untrusted code is executed in sandboxed environments, such as Java Web Start applications, exposing users to risks when utilizing APIs that handle external data. As various versions of Oracle's Java products are affected, it is crucial for users to update their systems and review security settings to mitigate potential threats.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.14
Oracle GraalVM for JDK 17.0.15
Oracle GraalVM for JDK 21.0.7