Executive brief
Oracle GraalVM is a high-performance Java virtual machine that optimizes and executes Java applications. A vulnerability in the compiler component allows an unauthenticated attacker with network access to achieve complete system compromise, including data theft, modification, and denial of service.
Technical details
A difficult-to-exploit vulnerability exists in the Compiler component of Oracle GraalVM for JDK and Oracle GraalVM. The vulnerability is remotely exploitable over HTTP by an unauthenticated attacker without user interaction required. Successful exploitation results in complete compromise of the affected system, affecting confidentiality, integrity, and availability. The attack vector is network-based with high complexity, making it resistant to trivial exploitation attempts. Affected versions include GraalVM for JDK 17 (23.0.13.1), GraalVM for JDK 21 (23.1.12.1), and GraalVM (25.0.4.1).
Affected products
- Oracle GraalVM for JDK 17 23.0.13.1
- Oracle GraalVM for JDK 21 23.1.12.1
- Oracle GraalVM 25.0.4.1
Timeline
- 2026-09-15: disclosed