Junglewise Threat Intelligence

CVE-2026-46917: Oracle Java SE JSSE partial denial of service

CVE-2026-46917 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk. Vendors: Oracle.

Executive brief

A vulnerability exists in the Java Secure Socket Extension (JSSE) component of Oracle Java SE and GraalVM, which are widely used platforms for running enterprise applications. An unauthenticated attacker could exploit this flaw over a network to cause a partial denial of service, potentially disrupting the availability of web services or applications relying on these Java environments. This could lead to temporary service instability or performance degradation for customers and internal operations.

Technical details

This vulnerability is located in the Java Secure Socket Extension (JSSE) component of Oracle Java SE and GraalVM. It is classified as a denial of service (DoS) vulnerability that can be triggered by an unauthenticated attacker with network access via TLS. The exploit involves supplying malicious data to specific APIs within the JSSE component, typically through a web service interface. It does not require user interaction or elevated privileges. The impact is limited to a partial denial of service (Availability), with no reported impact on confidentiality or integrity. Affected versions include Java SE 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1, and specific GraalVM releases.

Affected products

  • Oracle Java SE 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
  • Oracle GraalVM for JDK 17.0.19, 21.0.11
  • Oracle GraalVM Enterprise Edition 21.3.18

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats