Impact
A vulnerability exists in the Compiler component of Oracle GraalVM that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can result in full control over the GraalVM instance, impacting confidentiality, integrity, and availability. The CVSS v3.1 score of 8.1 reflects a high severity attack that requires high attack complexity but no privileged access or user interaction.
Affected Systems
Oracle GraalVM, version 25.0.4.1, is the affected edition. The vulnerability is specific to the Compiler component of this product. No other versions or sub‑products are listed as impacted.
Risk and Exploitability
The CVSS base score indicates a significant risk, yet the EPSS score of probability of exploitation at this time. The vulnerability is not present in CISA’s KEV catalog. The likely attack vector is a remote unauthenticated HTTP connection to the GraalVM service, and because the vulnerability is described as difficult to exploit, a skilled attacker would need to precisely target the affected compiler functionality. Due to the potential for full system takeover, organizations should treat this as a high-priority risk.
OpenCVE Enrichment