Record summary

CVE-2026-21945 has a selected CVSS score of 7.5 (high).

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 21, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 56
ProductSourceVersion rangeStatus
CVE List21.3.16affected
CVE List17.0.17affected
21.0.9affected
CVE List8u471affected
8u471-b50affected
8u471-perfaffected
11.0.29affected
17.0.17affected
21.0.9affected
25.0.1affected

OPENJDK ELS 11.0.30

Browse Red Hat / OPENJDK ELS 11.0.30java-11

Default status: affected

CVE Listopenjdk-portable to < *unaffected
openjdk-windows to < *unaffected

Red Hat Build of OpenJDK 17.0.18

Browse Red Hat / Red Hat Build of OpenJDK 17.0.18java-17

Default status: affected

CVE Listopenjdk-portable to < *unaffected
openjdk-windows to < *unaffected

Red Hat Build of OpenJDK 21.0.10

Browse Red Hat / Red Hat Build of OpenJDK 21.0.10java-21

Default status: affected

CVE Listopenjdk-portable to < *unaffected
openjdk-windows to < *unaffected

Red Hat Build of OpenJDK 25.0.2

Browse Red Hat / Red Hat Build of OpenJDK 25.0.2java-25

Default status: affected

CVE Listopenjdk-portable to < *unaffected

Red Hat Build of OpenJDK 8u482

Browse Red Hat / Red Hat Build of OpenJDK 8u482java-1.8.0

Default status: affected

CVE Listopenjdk-portable to < *unaffected
openjdk-windows to < *unaffected

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10java-21-ibm-semeru-certified-jdk

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10java-21-openjdk

Default status: affected

CVE List1:21.0.10.0.7-1.el10 to < *unaffected

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10java-25-openjdk

Default status: affected

CVE List1:25.0.2.0.10-1.el10 to < *unaffected

Red Hat Enterprise Linux 10.0 Extended Update Support

Browse Red Hat / Red Hat Enterprise Linux 10.0 Extended Update Supportjava-21-openjdk

Default status: affected

CVE List1:21.0.10.0.7-1.el10 to < *unaffected

References

Showing 12 of 19