Description
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the JavaFX component of Oracle Java SE 8u491. An unauthenticated attacker who can reach the JavaFX APIs over a network protocol can trigger a partial denial of service. Successful exploitation does not grant code execution or privilege escalation; it simply disrupts the availability of the JavaFX component, causing services that rely on it to become unavailable or sluggish. The weakness is a classic example of CWE‑770, Excessive Resource Consumption.

Affected Systems

Oracle Java SE 8u491 is the affected version. The vulnerability applies to any deployment that exposes the JavaFX API, including clients running Java Web Start applications or sandboxed Java applets that load untrusted code via the internet.

Risk and Exploitability

The CVSS 3.1 base score of 5.3 indicates moderate severity focused on availability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild at present, and the vulnerability is not cataloged in CISA’s KEV. The likely attack vector is an unauthenticated network attacker who can reach the JavaFX API endpoints with standard protocol calls.

Generated by OpenCVE AI on August 4, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Oracle Java SE update that patches JavaFX, such as 8u492 or later, as soon as it is available.
  • Restrict inbound network traffic to the JavaFX API endpoints by configuring firewall or access control to trusted hosts only.
  • If JavaFX is not required, disable or remove the JavaFX libraries from the JVM to eliminate the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title JavaFX Excessive Resource Consumption Exploitation Causes Partial Denial of Service in Oracle Java SE 8u491

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote API Exploit in Oracle JavaFX Causing Partial Denial of Service

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote API Exploit in Oracle JavaFX Causing Partial Denial of Service

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:09:00.192Z

Reserved: 2026-05-18T15:55:10.317Z

Link: CVE-2026-47013

cve-icon Vulnrichment

Updated: 2026-07-23T15:08:48.011Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:06.857

Modified: 2026-07-31T14:52:14.140

Link: CVE-2026-47013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling