Severity
7.5HIGH
EPSS
0.1%
top 82.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateDec 1

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Orac

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

CVEListV5oracle_corporation/oracle_java_se6 versions+5
NVDoracle/graalvm21.3.15, 17.0.16, 21.0.8+2
CVEListV5oracle_corporation/oracle_graalvm_for_jdk17.0.16, 21.0.8+1
NVDoracle/jdk5 versions+4

🔴Vulnerability Details

11
OSV
openjdk-17-crac vulnerabilities2025-12-01
OSV
openjdk-25-crac vulnerabilities2025-12-01
OSV
openjdk-21-crac vulnerabilities2025-12-01
OSV
openjdk-17 vulnerabilities2025-11-24
OSV
openjdk-8 vulnerabilities2025-11-24

📋Vendor Advisories

13
Ubuntu
CRaC JDK 25 vulnerabilities2025-12-01
Ubuntu
CRaC JDK 21 vulnerabilities2025-12-01
Ubuntu
CRaC JDK 17 vulnerabilities2025-12-01
Ubuntu
OpenJDK 11 vulnerabilities2025-11-24
Ubuntu
OpenJDK 17 vulnerabilities2025-11-24
CVE-2025-53066 (HIGH CVSS 7.5) | Vulnerability in the Oracle Java SE | cvebase.io