Network Access Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-22021
5.3MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 April 2026
What is CVE-2026-22021?
This vulnerability in Oracle Java SE and GraalVM products exposes affected systems to unauthenticated network access via HTTPS, which allows attackers to exploit specific APIs in the component. This can lead to partial denial of service, particularly affecting Java environments that run untrusted code from external sources. The vulnerability's exploitation potential highlights the need for prompt mitigation and solution implementation to safeguard Java applications.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.17
Oracle GraalVM for JDK 17.0.18
Oracle GraalVM for JDK 21.0.10