Executive brief
Oracle Java SE, GraalVM, and related runtime environments contain a denial-of-service vulnerability in their TLS/SSL component (JSSE). An unauthenticated attacker with network access can exploit this flaw by sending specially crafted data to Java applications, causing partial service interruptions. This impacts Java-based web services and applications that process TLS connections.
Technical details
The vulnerability exists in the JSSE (Java Secure Socket Extension) component and is easily exploitable via TLS without requiring authentication. It can be triggered by supplying malicious data to APIs in the affected component through network-reachable services such as web services. The vulnerability results in partial denial of service (availability impact) but does not allow data breach or system compromise. Successful exploitation causes a partial disruption to service availability. Patches are available through Oracle's security updates for the affected Java SE versions and GraalVM editions.
Affected products
- Oracle Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2
- Oracle GraalVM for JDK 17.0.20, 21.0.12
- Oracle GraalVM Enterprise Edition 21.3.19
Timeline
- 2026-08-18: disclosed