Junglewise Threat Intelligence

CVE-2026-21945: Oracle Java SE and GraalVM denial of service in Security component

CVE-2026-21945 · Severity: high · CVSS 7.5 · Published 2026-01-20

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk, Siemens SIMATIC CN 4100. Vendors: Oracle, Red Hat, Siemens.

Executive brief

A vulnerability in the security component of Oracle Java and GraalVM can allow an unauthenticated attacker to remotely crash or freeze the software. This issue primarily affects client-side Java deployments that run untrusted code from the internet, such as sandboxed applets. An exploit could lead to a complete denial of service, disrupting business operations and application availability.

Technical details

A vulnerability exists in the Security component of Oracle Java SE and GraalVM related to improper certificate validation (CWE-295) and uncontrolled resource consumption (CWE-400). The flaw is easily exploitable by an unauthenticated attacker with network access via multiple protocols. Successful exploitation allows an attacker to cause a frequently repeatable crash or a hang, resulting in a complete denial of service (DoS). This vulnerability specifically impacts Java deployments that rely on the Java sandbox to run untrusted code, such as Java Web Start applications. Server-side deployments running only trusted code are generally not affected. Patches are available through Oracle's January 2026 Critical Patch Update and Red Hat's security advisories.

Affected products

  • Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1
  • Oracle GraalVM for JDK 17.0.17, 21.0.9
  • Oracle GraalVM Enterprise Edition 21.3.16
  • Red Hat OpenJDK 11 ELS 11.0.29

Timeline

  • 2026-01-20: advisory: Initial disclosure by Oracle and NVD publication
  • 2026-01-21: patched: Red Hat released security updates for OpenJDK 11 ELS

References

Related threats