Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle has identified an easily exploitable flaw in the JSSE component of its Java SE and GraalVM products that allows an unauthenticated attacker with network access to the TLS channel to send crafted traffic and cause a partial denial of service. The flaw does not grant confidentiality or integrity compromise; it simply interrupts the availability of the affected Java runtime. The vulnerability is triggered by supplying malformed or specially crafted data to the TLS APIs – no trusted web‑start or applet contexts are required. This flaw is classified as CWE‑284.

Affected Systems

Affected vendors and products are Oracle Java SE, Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition. The following versions are impacted: Oracle Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition 21.3.19. All other releases remain unaltered unless they include the same JSSE code base.

Risk and Exploitability

The CVSS v3.1 score is 5.3, reflecting a moderate availability impact and a low authentication requirement. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that it has not yet been seen in the wild. The attack vector is network-based via TLS; an unauthenticated attacker can initiate the exploit by transmitting crafted TLS records to any service that relies on the vulnerable Java runtime. Successful exploitation results in a partial denial of service for that particular service.

Generated by OpenCVE AI on August 21, 2026 at 04:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a newer release of Oracle Java SE, Oracle GraalVM for JDK, or Oracle GraalVM Enterprise Edition that addresses the JSSE flaw
  • Configure systems to reject or drop malformed TLS records using a network firewall or intrusion‑prevention device, and monitor for abnormal TLS connection attempts
  • If an immediate upgrade is not possible, limit TLS access to trusted hosts only and consider temporarily disabling the vulnerable Java runtime for nonessential services

Generated by OpenCVE AI on August 21, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4756-1 openjdk-11 security update
Debian DLA Debian DLA DLA-4757-1 openjdk-17 security update
Debian DSA Debian DSA DSA-6457-1 openjdk-21 security update
Debian DSA Debian DSA DSA-6460-1 openjdk-25 security update
History

Thu, 20 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle graalvm Enterprise Edition
Vendors & Products Oracle graalvm Enterprise Edition

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title OpenJDK: Enhance TLS server (2026-08 Security Update)
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Eus
Redhat hummingbird
Redhat openjdk
Redhat openjdk Els
Redhat rhel E4s
Redhat rhel Els
Redhat rhel Eus
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openjdk:1.8
cpe:/a:redhat:openjdk:17
cpe:/a:redhat:openjdk:21
cpe:/a:redhat:openjdk:25
cpe:/a:redhat:openjdk_els:11::el7
cpe:/a:redhat:openjdk_els:11::el8
cpe:/a:redhat:openjdk_els:11::el9
cpe:/a:redhat:rhel_e4s:9.4
cpe:/a:redhat:rhel_eus:9.6
cpe:/o:redhat:enterprise_linux:10.2
cpe:/o:redhat:enterprise_linux_eus:10.0
cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Eus
Redhat hummingbird
Redhat openjdk
Redhat openjdk Els
Redhat rhel E4s
Redhat rhel Els
Redhat rhel Eus
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via TLS in Oracle Java SE and GraalVM
Weaknesses CWE-749

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via TLS in Oracle Java SE and GraalVM
Weaknesses CWE-749

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
CPEs cpe:2.3:a:oracle:graalvm:21.3.19:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:11.0.32:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u501:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Graalvm Graalvm Enterprise Edition Graalvm For Jdk Java Se
Redhat Enterprise Linux Enterprise Linux Eus Hummingbird Openjdk Openjdk Els Rhel E4s Rhel Els Rhel Eus
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:10.509Z

Reserved: 2026-08-04T22:06:34.605Z

Link: CVE-2026-70907

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:30.420Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:17:48.513

Modified: 2026-08-20T13:08:14.613

Link: CVE-2026-70907

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T09:09:00Z

Links: CVE-2026-70907 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:45:03Z

Weaknesses