Oracle Java SE and GraalVM for JDK Compiler Component Denial-of-Service Vulnerability

Vulnerability

A vulnerability has been identified in Oracle Java SE and Oracle GraalVM for JDK, both in version 24.0.1, within the Compiler component. This vulnerability allows an unauthenticated attacker with network access to compromise the affected Java environments. Exploitation of this vulnerability can lead to a partial denial-of-service condition, causing disruptions in the normal functioning of the Java application. The issue is particularly relevant for Java deployments that execute untrusted code from the internet, such as sandboxed Java Web Start applications or applets, and rely on the Java security sandbox. In contrast, deployments on servers that only run trusted code are not affected.

Impact

Exploitation of this vulnerability can cause a partial denial-of-service condition, disrupting the normal operation of Oracle Java SE or Oracle GraalVM for JDK.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.7
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.