CVE-2025-30752

Severity
3.7LOW
EPSS
0.1%
top 79.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle Java SE: 24.0.1; Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages5 packages

NVDoracle/graalvm24.0.1
NVDoracle/jdk24.0.1
NVDoracle/jre24.0.1

🔴Vulnerability Details

3
GHSA
GHSA-ffx9-x7f3-xr9v: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler)2025-07-15
CVEList
CVE-2025-30752: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler)2025-07-15
OSV
CVE-2025-30752: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler)2025-07-15

📋Vendor Advisories

1
Oracle
Oracle Oracle Java SE Risk Matrix: Compiler — CVE-2025-307522025-07-15