Network Access Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-22021

5.3MEDIUM

What is CVE-2026-22021?

This vulnerability in Oracle Java SE and GraalVM products exposes affected systems to unauthenticated network access via HTTPS, which allows attackers to exploit specific APIs in the component. This can lead to partial denial of service, particularly affecting Java environments that run untrusted code from external sources. The vulnerability's exploitation potential highlights the need for prompt mitigation and solution implementation to safeguard Java applications.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.17

Oracle GraalVM for JDK 17.0.18

Oracle GraalVM for JDK 21.0.10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.