Junglewise Threat Intelligence

CVE-2025-53066: Oracle Java SE and GraalVM Information Exposure in JAXP

CVE-2025-53066 · Severity: high · CVSS 7.5 · Published 2025-10-21

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk. Vendors: Oracle, Debian.

Executive brief

A vulnerability exists in the Java XML processing component (JAXP) used by Oracle Java and GraalVM to handle structured data. An unauthenticated attacker could exploit this over a network to gain unauthorized access to sensitive information or all data accessible by the Java application. This is particularly critical for web services that process XML data or client-side applications running untrusted code in a sandbox.

Technical details

This vulnerability is located in the Java API for XML Processing (JAXP) component of Oracle Java SE and GraalVM. It is classified as an Information Exposure (CWE-200) and, according to Debian advisories, may specifically relate to XML External Entity (XXE) injection or incorrect certificate validation. The flaw is easily exploitable by an unauthenticated attacker with network access via multiple protocols, typically by providing malicious XML data to a web service or application that utilizes the affected JAXP APIs. Successful exploitation allows for unauthorized access to critical data, bypassing intended confidentiality controls. Oracle addressed this in the October 2025 Critical Patch Update, and OpenJDK updates (e.g., 11.0.29+6) are available.

Affected products

  • Oracle Java SE 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25
  • Oracle GraalVM for JDK 17.0.16, 21.0.8
  • Oracle GraalVM Enterprise Edition 21.3.15
  • Debian openjdk-11 before 11.0.29+6-1~deb11u1

Timeline

  • 2025-10-21: advisory: Initial Oracle advisory published
  • 2025-10-21: disclosed
  • 2025-10-25: patched: Debian released openjdk-11 security update

References

Related threats