Impact
Oracle has identified an easily exploitable flaw in the JSSE component of its Java SE and GraalVM products that allows an unauthenticated attacker with network access to the TLS channel to send crafted traffic and cause a partial denial of service. The flaw does not grant confidentiality or integrity compromise; it simply interrupts the availability of the affected Java runtime. The vulnerability is triggered by supplying malformed or specially crafted data to the TLS APIs – no trusted web‑start or applet contexts are required. This flaw is classified as CWE‑284.
Affected Systems
Affected vendors and products are Oracle Java SE, Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition. The following versions are impacted: Oracle Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition 21.3.19. All other releases remain unaltered unless they include the same JSSE code base.
Risk and Exploitability
The CVSS v3.1 score is 5.3, reflecting a moderate availability impact and a low authentication requirement. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that it has not yet been seen in the wild. The attack vector is network-based via TLS; an unauthenticated attacker can initiate the exploit by transmitting crafted TLS records to any service that relies on the vulnerable Java runtime. Successful exploitation results in a partial denial of service for that particular service.
OpenCVE Enrichment
Debian DLA
Debian DSA