Junglewise Threat Intelligence

CVE-2026-47027: Oracle Java SE denial of service in Libraries

CVE-2026-47027 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk. Vendors: Oracle.

Executive brief

A vulnerability exists in the core libraries of Oracle Java SE, a widely used platform for running business applications and web services. An attacker could exploit this flaw to cause a partial denial of service, potentially slowing down or crashing specific Java-based services. This issue also affects client-side Java applications that run untrusted code from the internet, such as those using Java Web Start.

Technical details

This vulnerability is located in the Libraries component of Oracle Java SE and GraalVM. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the environment. The primary impact is a partial denial of service (availability impact). The vulnerability can be triggered by supplying malicious data to specific APIs, such as through a web service, or by executing untrusted code within sandboxed Java Web Start or applet environments. Affected versions include Java SE 8u491 through 26.0.1 and various GraalVM releases.

Affected products

  • Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
  • Oracle GraalVM for JDK 17.0.19, 21.0.11
  • Oracle GraalVM Enterprise Edition 21.3.18

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-47027

References

Related threats