Impact
The flaw resides in the Java Secure Socket Extension (JSSE) component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. An unauthenticated attacker who can reach the system over TLS can send crafted DTLS traffic that triggers a resource exhaustion condition within the SSL/TLS stack, resulting in a partial denial of service. The weakness is a resource management issue (CWE‑400) combined with improper access control (CWE‑284) in the DTLS handshake logic. Only availability is affected; confidentiality and integrity remain intact.
Affected Systems
Affecteed versions include Oracle Java SE 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. Systems running any of these releases that expose TLS/DTLS interfaces to untrusted clients are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 highlights a low‑to‑moderate impact limited to availability. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, requiring the attacker to initiate a DTLS connection using crafted packets to trigger the resource exhaustion path. Although exploitation is unlikely, services that rely heavily on TLS/DTLS could suffer intermittent disruptions if no mitigation is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA