Impact
A flaw in Oracle GraalVM for JDK and Oracle GraalVM allows an unauthenticated attacker with network access via HTTP to compromise the JVM. The vulnerability is first‑party, and the affected component is the compiler. Successful exploitation can lead to a full takeover of the affected GraalVM instance, impacting confidentiality, integrity, and availability as reflected by the CVSS vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The weakness involves improper access control of HTTP services, which would permit remote code execution.
Affected Systems
The affected products are Oracle GraalVM for JDK version 23.0.13.1 (Java 17) and 23.1.12.1 (Java 21) as well as Oracle GraalVM version 25.0.4.1. These versions are distributed under the Oracle GraalVM product line.
Risk and Exploitability
The CVSS score of 8.1 places this flaw in the high‑severity category. The EPSS score is below 1 %, indicating a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP, requires no authentication or user interaction, and involves high effort to exploit as indicated by the high attack complexity rating.
OpenCVE Enrichment