Executive brief
Oracle GraalVM is a high-performance Java virtual machine used to run Java applications. A vulnerability in its compiler component allows remote attackers to take over systems running affected versions of GraalVM without authentication. Successful exploitation results in complete compromise of confidentiality, integrity, and availability of the affected system.
Technical details
A remote code execution vulnerability exists in the Oracle GraalVM compiler component affecting versions GraalVM for JDK 17 (23.0.13.1), GraalVM for JDK 21 (23.1.12.1), and GraalVM (25.0.4.1). The vulnerability is triggered via network access over HTTP and requires high complexity but no authentication or user interaction. An unauthenticated remote attacker can exploit this to achieve complete system compromise including unauthorized code execution, data exposure, and system disruption. The vulnerability is classified as difficult to exploit due to its attack complexity requirements.
Affected products
- Oracle GraalVM for JDK 17 23.0.13.1
- Oracle GraalVM for JDK 21 23.1.12.1
- Oracle GraalVM 25.0.4.1
Timeline
- 2026-09-15: disclosed