Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-47059

3.7LOW

What is CVE-2026-47059?

This vulnerability allows unauthenticated attackers with network access to exploit certain versions of Oracle Java SE and GraalVM products. When successfully exploited, the vulnerability can lead to a partial denial of service. It primarily affects users running sandboxed Java applications that load untrusted code from the internet. Environments that operate Java applications with trusted code are not impacted. Addressing this issue is critical to enhance the security of Java deployments.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.18

Oracle GraalVM for JDK 17.0.19

Oracle GraalVM for JDK 21.0.11

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.