Impact
A vulnerability in the Libraries component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows an unauthenticated attacker who has network access to exploit APIs available through multiple protocols. Successful exploitation can cause a partial denial of service, disrupting application availability but not compromising confidentiality or integrity. The weakness is similar to a resource exhaustion or availability control failure, as it is broadly described as "partial DOS" based on usage of vulnerable APIs.
Affected Systems
Affected vendors include Oracle Corporation. The vulnerable products are Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Versions that can be compromised are Java SE 8u481, 8u481‑b50, 8u481‑perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26; GraalVM for JDK 17.0.18 and 21.0.10; and GraalVM Enterprise Edition 21.3.17.
Risk and Exploitability
The CVSS score of 3.7 indicates a low‑to‑moderate severity. The attack vector is Network, with high attack complexity, no prerequisites, and no user interaction required. While EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, the fact that it can be triggered without authentication and across multiple protocols raises the likelihood of exploitation for organizations that expose Java services to the internet. If exploited, an attacker can disrupt services, potentially affecting end‑users or downstream systems that rely on the affected Java components.
OpenCVE Enrichment