Oracle Java SE and GraalVM Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The affected versions include Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1, as well as Oracle GraalVM for JDK 17.0.17 and 21.0.9, and Oracle GraalVM Enterprise Edition 21.3.16. This vulnerability allows an unauthenticated attacker with network access to compromise these Java environments, particularly in client-side deployments running sandboxed Java Web Start applications or applets that execute untrusted code from the internet. Exploitation of this vulnerability can lead to a complete denial-of-service, causing the Java application or environment to hang or crash frequently and repetitively.

Impact

Exploitation of this vulnerability can cause a complete denial-of-service, leading to a frequent and repeatable crash or hang of the affected Java environment.

Added: Jan 20, 2026, 11:08 PM
Updated: Jan 20, 2026, 11:08 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.3
remediation
0.0
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.