Description
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability exists in the Scripting component of Oracle Java SE. The flaw allows an unauthenticated attacker with network access to trigger a denial‑of‑service condition by forcing the JVM to hang or crash repeatedly. Because the weakness resides in a core runtime function, any Java application or service that invokes the scripting engine through exposed APIs can be impacted, including server‑side web services and sandboxed client apps that load untrusted code.

Affected Systems

Oracle Corporation’s Oracle Java SE has known vulnerable releases 8u491, 8u491‑perf, and 11.0.31. These versions are used in both server‑side deployments and legacy client applications that rely on the Java runtime for scripting tasks.

Risk and Exploitability

The CVSS base score of 7.5 highlights a high availability impact, while the EPSS score of less than 1% indicates that exploitation is currently unlikely but possible. The vulnerability can be triggered remotely over a variety of network protocols; the description notes that APIs in the affected component can be invoked, for example, via a web service that accepts data. The attack requires no authentication and can be performed by any host that can reach the Java runtime, making the risk significant for exposed services and for client environments that load external scripts.

Generated by OpenCVE AI on August 4, 2026 at 04:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Java SE update that addresses the scripting component vulnerability (e.g., upgrade to 8u492+ or 11.0.32+).
  • If an immediate update is not feasible, restrict untrusted Java runtime usage by disabling the scripting component (e.g., Nashorn) or removing it altogether from the deployed runtime.
  • For client deployments that must continue using the vulnerable runtime, isolate Java applets or Web Start applications in a sandboxed environment, monitor them for instability, block repeated hangs, and set application‑level timeouts.

Generated by OpenCVE AI on August 4, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4702-1 openjdk-11 security update
History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title openjdk: OpenJDK: Improve Nashorn index handling (Oracle CPU 2026-07)
Weaknesses CWE-190
References
Metrics threat_severity

None

threat_severity

Important


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:enterprise_performance:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:06:51.646Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47057

cve-icon Vulnrichment

Updated: 2026-07-23T16:06:42.351Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:11.483

Modified: 2026-08-03T18:52:45.383

Link: CVE-2026-47057

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T20:00:00Z

Links: CVE-2026-47057 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-400

    Uncontrolled Resource Consumption