CVE-2026-22008
published 2026-04-21CVE-2026-22008: Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability…
PriorityP414low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EPSS
0.21%
10.8th percentile
Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle_corporation | oracle_java_se | — | — |
| ubuntu | openjdk-25 | — | — |
| ubuntu | openjdk-25-crac | — | — |
| ubuntu | openjdk-26 | — | — |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat3.7LOW
vendor_ubuntu2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 25 vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 2.9
CVE-2026-22008 [LOW] OpenJDK 25 vulnerabilities
Title: OpenJDK 25 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 25.
Thomas Beckers discovered that the JAXP component of OpenJDK 25 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to gain unauthorized access to sensitive
information. (CVE-2026-22016)
It was discovered that the Networking component of OpenJDK 25 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-34282)
It was discovered that the JSSE component of OpenJDK 25 did not correctly
authenticate certain APIs. A remote unauthenticated attacker could possibly
use this issue to cause a denial of service. (CVE-2026-22021)
It was discovered that the J
Ubuntu
CRaC JDK 25 vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 2.9
CVE-2026-22008 [LOW] CRaC JDK 25 vulnerabilities
Title: CRaC JDK 25 vulnerabilities
Summary: Several security issues were fixed in CRaC JDK 25.
Thomas Beckers discovered that the JAXP component of CRaC JDK 25 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to gain unauthorized access to sensitive
information. (CVE-2026-22016)
It was discovered that the Networking component of CRaC JDK 25 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-34282)
It was discovered that the JSSE component of CRaC JDK 25 did not correctly
authenticate certain APIs. A remote unauthenticated attacker could possibly
use this issue to cause a denial of service. (CVE-2026-22021)
It was discovered that
Ubuntu
OpenJDK 26 vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 2.9
CVE-2026-22008 [LOW] OpenJDK 26 vulnerabilities
Title: OpenJDK 26 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 26.
Thomas Beckers discovered that the JAXP component of OpenJDK 26 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to gain unauthorized access to sensitive
information. (CVE-2026-22016)
It was discovered that the Networking component of OpenJDK 26 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-34282)
It was discovered that the JSSE component of OpenJDK 26 did not correctly
authenticate certain APIs. A remote unauthenticated attacker could
possibly use this issue to cause a denial of service. (CVE-2026-22021)
It was discovered that the J
Red Hat
openjdk: OpenJDK: Improved Arena allocations (Oracle CPU 2026-04)
vendor_redhat·2026-04-21·CVSS 3.7
CVE-2026-22008 [LOW] CWE-122 openjdk: OpenJDK: Improved Arena allocations (Oracle CPU 2026-04)
openjdk: OpenJDK: Improved Arena allocations (Oracle CPU 2026-04)
No description is available for this CVE.
Package: java-11-openjdk (Red Hat build of OpenJDK 11 ELS) - Not affected
Package: java-11-openjdk-portable (Red Hat build of OpenJDK 11 ELS) - Not affected
Package: java-11-openjdk-windows (Red Hat build of OpenJDK 11 ELS) - Not affected
Package: java-17-openjdk-portable (Red Hat build of OpenJDK 17) - Not affected
Package: java-17-openjdk-windows (Red Hat build of OpenJDK 17) - Not affected
Package: java-1.8.0-openjdk-portable (Red Hat build of OpenJDK 1.8) - Not affected
Package: java-1.8.0-openjdk-windows (Red Hat build of OpenJDK 1.8) - Not affected
Package: java-21-openjdk-portable (Red Hat build of OpenJDK 21) - Not affected
Package: java-21-openjdk-windows (Red Hat
VulDB
Oracle Java SE 25.0.1 Libraries improper authorization (Nessus ID 309648 / WID-SEC-2026-1201)
vuldb·2026-05-03·CVSS 3.7
CVE-2026-22008 [LOW] Oracle Java SE 25.0.1 Libraries improper authorization (Nessus ID 309648 / WID-SEC-2026-1201)
A vulnerability categorized as critical has been discovered in Oracle Java SE 25.0.1. This affects an unknown part of the component Libraries. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-22008. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-ffgj-wmrh-m8fr: Vulnerability in Oracle Java SE (component: Libraries)
ghsa_unreviewed·2026-04-21
CVE-2026-22008 [LOW] CWE-250 GHSA-ffgj-wmrh-m8fr: Vulnerability in Oracle Java SE (component: Libraries)
Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code inst
No detection rules found.
No public exploits indexed.
2026-04-21
Published