Impact
The vulnerability resides in the 2D image handling of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. An unauthenticated attacker that can send specially crafted XBM image data through any network‑facing protocol can trigger a crash or resource exhaustion, resulting in a partial denial of service. The weakness is identified as CWE‑1333 (Imbalanced Resource Allocation) and CWE‑400 (Uncontrolled Resource Consumption).
Affected Systems
Affected deployments include Oracle Java SE versions 8u491 (including the 8u491‑perf variant), 11.0.31, 17.0.19, 21.0.11, 25.0.3 and 26.0.1; Oracle GraalVM for JDK versions 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. Any installation that exposes APIs which accept XBM image data—such as web services, Java Web Start, or sandboxed applets—is at risk when running these versions.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 signals a low‑to‑moderate availability impact. The EPSS score is below 1 %, indicating a low likelihood of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely without authentication by transmitting malicious XBM image data via any network fronting the vulnerable Java API or web service. Based on the description, it is inferred that the primary attack vector is delivery of crafted XBM image data through a network‑facing Java API, such as a web service, Java Web Start or sandboxed applet that accepts image input. A successful exploit simply functions to crash or hang the Java runtime, resulting in a partial service interruption.
OpenCVE Enrichment
Debian DLA
Debian DSA