Description
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-08-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Oracle Java SE 2D component and allows an unauthenticated attacker with network access to supply crafted data to vulnerable APIs. When that data is processed, Oracle Java SE can hang or repeatedly crash, resulting in a denial of service for Java applications that use the affected component. This issue does not compromise confidentiality or integrity; it solely impacts availability.

Affected Systems

Oracle Java SE 7u511 is affected. The vulnerability impacts the Java 2D component used by Java Web Start applications or sandboxed applets that rely on the Java sandbox to execute untrusted code.

Risk and Exploitability

Based on the CVSS score of 6.5 this vulnerability is rated as medium severity, with the primary impact on availability. The attack vector is an unauthenticated network attacker who can send malicious data to the vulnerable 2D APIs. Because no EPSS value is provided, the proportion of active exploitation cannot be precisely quantified. It is inferred that the risk is moderate in environments where the affected Java runtime is exposed to untrusted input. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread or confirmed exploitation has been observed in the wild.

Generated by OpenCVE AI on August 26, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Java SE to the latest patch that addresses the 2D component issue (e.g., from Oracle support)
  • If a patch is not yet available, temporarily limit exposure of Java applications to untrusted network input by disabling unnecessary network interfaces or isolating Java services
  • Apply configuration changes to the Java sandbox to refuse execution of untrusted code until a secure update is deployed
  • Monitor application logs for repeated crashes or hangs to detect attempted exploitation

Generated by OpenCVE AI on August 26, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle Java SE 2D Component Denial of Service via Untrusted Data

Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T20:25:09.364Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71054

cve-icon Vulnrichment

Updated: 2026-08-26T20:25:03.856Z

cve-icon NVD

Status : Received

Published: 2026-08-26T20:17:58.897

Modified: 2026-08-26T21:16:40.420

Link: CVE-2026-71054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:00:14Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling