Executive brief
A vulnerability exists in the 2D graphics component of Oracle Java and GraalVM, which are widely used platforms for running software applications. An attacker could potentially cause a partial service disruption, making the application temporarily unavailable or unstable. This issue primarily affects desktop users running untrusted Java applications from the internet, rather than standard server environments.
Technical details
This vulnerability resides in the 2D component of Oracle Java SE and GraalVM. It is classified as a denial of service (DoS) vulnerability that can be triggered by an unauthenticated attacker via multiple network protocols. The attack complexity is rated as high, suggesting specific conditions or configurations are required for successful exploitation. The impact is limited to a partial loss of availability. This flaw specifically targets sandboxed environments, such as Java Web Start or applets, where untrusted code is executed; it does not typically affect server-side deployments running trusted administrative code. Patching information is referenced in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
- Oracle GraalVM for JDK 17.0.19, 21.0.11
- Oracle GraalVM Enterprise Edition 21.3.18
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory