Impact
The vulnerability lies in the way the Java Development Kit processes JAR files, allowing an unauthenticated attacker to manipulate the API that loads JAR data. This flaw triggers a resource exhaustion condition (CWE‑400) and is further compounded by improper access control (CWE‑284), which permits the exploitation without authentication. A network‑based attacker can initiate the exploit through multiple protocols, potentially via a web service or any other interface that feeds data to the vulnerable API. The impact is a partial denial of service, where the attacker can reduce service availability by exhausting resources, and it also poses a risk to sandboxed Java Web Start applications or applets that rely on the JAR processing logic for untrusted code.
Affected Systems
Oracle Java SE versions 8u491, 8u491‑perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition 21.3.18 are all impacted.
Risk and Exploitability
The CVSS Base Score of 5.3 indicates a moderate availability impact, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based, utilizing exposed APIs or services that process JAR files from untrusted sources. Attackers would need no special privileges or authentication to initiate the attack, which can lead to resource exhaustion and reduced service availability.
OpenCVE Enrichment
Debian DLA
Debian DSA