Severity
5.9MEDIUM
EPSS
0.1%
top 77.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateDec 1

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages18 packages

CVEListV5oracle_corporation/oracle_java_se6 versions+5
NVDoracle/graalvm21.3.15, 17.0.16, 21.0.8+2
CVEListV5oracle_corporation/oracle_graalvm_for_jdk17.0.16, 21.0.8+1
NVDoracle/jdk5 versions+4

🔴Vulnerability Details

11
OSV
openjdk-21-crac vulnerabilities2025-12-01
OSV
openjdk-17-crac vulnerabilities2025-12-01
OSV
openjdk-25-crac vulnerabilities2025-12-01
OSV
openjdk-8 vulnerabilities2025-11-24
OSV
openjdk-17 vulnerabilities2025-11-24

📋Vendor Advisories

12
Ubuntu
CRaC JDK 25 vulnerabilities2025-12-01
Ubuntu
CRaC JDK 21 vulnerabilities2025-12-01
Ubuntu
CRaC JDK 17 vulnerabilities2025-12-01
Ubuntu
OpenJDK 11 vulnerabilities2025-11-24
Ubuntu
OpenJDK 17 vulnerabilities2025-11-24
CVE-2025-53057 (MEDIUM CVSS 5.9) | Vulnerability in the Oracle Java SE | cvebase.io