Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Java Secure Socket Extension (JSSE) component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. An unauthenticated attacker who can reach the system over TLS can send crafted DTLS traffic that triggers a resource exhaustion condition within the SSL/TLS stack, resulting in a partial denial of service. The weakness is a resource management issue (CWE‑400) combined with improper access control (CWE‑284) in the DTLS handshake logic. Only availability is affected; confidentiality and integrity remain intact.

Affected Systems

Affecteed versions include Oracle Java SE 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. Systems running any of these releases that expose TLS/DTLS interfaces to untrusted clients are at risk.

Risk and Exploitability

The CVSS v3.1 base score of 5.3 highlights a low‑to‑moderate impact limited to availability. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, requiring the attacker to initiate a DTLS connection using crafted packets to trigger the resource exhaustion path. Although exploitation is unlikely, services that rely heavily on TLS/DTLS could suffer intermittent disruptions if no mitigation is applied.

Generated by OpenCVE AI on August 3, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Java SE, Oracle GraalVM for JDK, or Oracle GraalVM Enterprise Edition update that contains the patch for this vulnerability.
  • Disable or restrict DTLS where it is not required so that the vulnerable code paths are no longer exposed to untrusted traffic.
  • Implement TLS/DTLS rate limiting or packet inspection at the network perimeter to detect and block anomalous handshake attempts.

Generated by OpenCVE AI on August 3, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4702-1 openjdk-11 security update
Debian DLA Debian DLA DLA-4703-1 openjdk-17 security update
Debian DSA Debian DSA DSA-6425-1 openjdk-21 security update
History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle graalvm Enterprise Edition
Vendors & Products Oracle graalvm Enterprise Edition

Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title openjdk: OpenJDK: Improve DTLS handshaking (Oracle CPU 2026-07)
Weaknesses CWE-400
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
CPEs cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Graalvm Graalvm Enterprise Edition Graalvm For Jdk Java Se
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:19:18.407Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46917

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:54.281Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T20:00:00Z

Links: CVE-2026-46917 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption