Executive brief
A vulnerability in the security component of Oracle Java and GraalVM can allow an unauthenticated attacker to remotely crash or freeze the software. This issue primarily affects client-side Java deployments that run untrusted code from the internet, such as sandboxed applets. An exploit could lead to a complete denial of service, disrupting business operations and application availability.
Technical details
A vulnerability exists in the Security component of Oracle Java SE and GraalVM related to improper certificate validation (CWE-295) and uncontrolled resource consumption (CWE-400). The flaw is easily exploitable by an unauthenticated attacker with network access via multiple protocols. Successful exploitation allows an attacker to cause a frequently repeatable crash or a hang, resulting in a complete denial of service (DoS). This vulnerability specifically impacts Java deployments that rely on the Java sandbox to run untrusted code, such as Java Web Start applications. Server-side deployments running only trusted code are generally not affected. Patches are available through Oracle's January 2026 Critical Patch Update and Red Hat's security advisories.
Affected products
- Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1
- Oracle GraalVM for JDK 17.0.17, 21.0.9
- Oracle GraalVM Enterprise Edition 21.3.16
- Red Hat OpenJDK 11 ELS 11.0.29
Timeline
- 2026-01-20: advisory: Initial disclosure by Oracle and NVD publication
- 2026-01-21: patched: Red Hat released security updates for OpenJDK 11 ELS
References
- https://www.oracle.com/security-alerts/cpujan2026.html
- https://access.redhat.com/errata/RHSA-2026:0847
- https://access.redhat.com/errata/RHSA-2026:0848
- https://access.redhat.com/errata/RHSA-2026:0895
- https://access.redhat.com/errata/RHSA-2026:0897
- https://access.redhat.com/errata/RHSA-2026:0899
- https://access.redhat.com/errata/RHSA-2026:0901