Junglewise Threat Intelligence

CVE-2026-47021: Oracle Java SE denial of service in 2D component

CVE-2026-47021 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk. Vendors: Oracle.

Executive brief

A vulnerability exists in the 2D graphics component of Oracle Java SE and GraalVM, which are widely used platforms for running enterprise applications and web services. An unauthenticated attacker could remotely exploit this flaw to cause a partial denial of service, potentially disrupting application availability or specific processing tasks. This issue is particularly relevant for systems that process external data through Java APIs or run untrusted code in sandboxed environments like Java Web Start.

Technical details

A vulnerability in the 2D component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows for a partial denial of service (DoS). The flaw is easily exploitable by an unauthenticated attacker with network access via multiple protocols. Exploitation can occur when a web service or application passes attacker-supplied data to affected 2D APIs, or when sandboxed Java deployments (like Java Web Start or applets) execute untrusted code. The vulnerability primarily impacts availability, as indicated by the CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L vector. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
  • Oracle GraalVM for JDK 17.0.19, 21.0.11
  • Oracle GraalVM Enterprise Edition 21.3.18

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication of CVE-2026-47021

References

Related threats