Network Access Vulnerability in Oracle Java SE and GraalVM by Oracle
CVE-2026-46917

5.3MEDIUM

What is CVE-2026-46917?

An unauthenticated attacker with network access can exploit a vulnerability in the Oracle Java SE and GraalVM products via TLS, leading to a potential partial denial of service. The flaw specifically allows for issues in the implementation of JSSE, where crafted data can be sent to the APIs of the affected components, impacting their availability. Users are advised to review the security alerts from Oracle to mitigate any risks.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.18

Oracle GraalVM for JDK 17.0.19

Oracle GraalVM for JDK 21.0.11

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.