Impact
Vulnerability: An internal flaw in the AWT 2D imaging library of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition can be triggered by unauthenticated network input and results in a partial denial of service, causing the Java process to terminate or become unresponsive; the flaw does not provide code execution or compromise confidentiality or integrity. It is identified as a combination of unauthorized access (CWE‑284) and null‑pointer dereference (CWE‑476).
Affected Systems
Affected by version: Oracle Java SE 8u491, 8u491‑perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition 21.3.18.
Risk and Exploitability
CVSS score 3.7 indicates low‑impact availability; EPSS <1% shows very low exploitation likelihood; not listed in CISA KEV. Attack vector: unattended server or client that uses Java Web Start or applet and can receive external network requests. The vulnerability is exploitable remotely, but the impact remains a service interruption rather than data theft or code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA