Network Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-34282

7.5HIGH

What is CVE-2026-34282?

An easily exploitable network vulnerability has been identified in Oracle Java SE and GraalVM products that allows unauthenticated attackers to cause persistent denial of service (DoS) conditions. By leveraging APIs in the Networking component, attackers can target deployed Java applications, including those running sandboxed Java Web Start applications or applets that execute untrusted code. This vulnerability can lead to significant disruptions, risking availability and stability of affected systems.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.17

Oracle GraalVM for JDK 17.0.18

Oracle GraalVM for JDK 21.0.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.