Executive brief
Oracle Java SE is a foundational runtime environment used to execute Java applications across servers, desktops, and browsers. A flaw in the 2D graphics component allows remote attackers to crash or hang Java applications without authentication, disrupting service availability. This affects both standalone Java applications and browser-based Java applets.
Technical details
The vulnerability is a denial-of-service flaw in the 2D component of Oracle Java SE, exploitable through multiple network protocols. An unauthenticated attacker with network access can trigger a hang or crash by crafting malicious input to the affected APIs, either directly or indirectly through a web service. The issue affects Java SE 7u511 and deployments using Java Web Start or sandboxed applets that load untrusted code. No authentication or user interaction is required; the attack is easily exploitable across the network.
Affected products
- Oracle Java SE 7u511
Timeline
- 2026-08-26: disclosed