CVE-2026-34282

7.5

Oracle · Java SE, GraalVM for JDK, GraalVM Enterprise Edition

A networking component vulnerability in Oracle Java SE and GraalVM allows unauthenticated remote attackers to cause a complete denial of service via multiple protocols.

Executive summary

An easily exploitable denial of service vulnerability in Oracle Java SE and GraalVM products allows unauthenticated remote attackers to crash systems, posing a significant availability risk.

Vulnerability

This is an easily exploitable flaw in the networking component that allows an unauthenticated attacker with network access to trigger a hang or repeatable crash, resulting in a complete denial of service.

Business impact

Successful exploitation of this vulnerability results in a complete denial of service for the affected Java applications. Given the CVSS score of 7.5, the high availability impact is significant for mission critical systems that rely on these Java environments, potentially leading to operational downtime and business disruption.

Remediation

Immediate Action: Review the official Oracle Critical Patch Update advisory for April 2026 and apply the necessary security patches to all affected Java environments.

Proactive Monitoring: Monitor network traffic for unusual patterns targeting Java APIs or web services, and review application server logs for frequent crashes or unexpected thread hangs.

Compensating Controls: Deploy Web Application Firewall rules to restrict access to exposed Java APIs or endpoints that process untrusted data, effectively reducing the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available unknown)

Analyst recommendation

Organizations should treat this vulnerability with high priority due to the ease of exploitation and the potential for service disruption. Administrators must audit their infrastructure to identify all instances of the affected Java versions and apply vendor-supplied updates as soon as they are made available to ensure system continuity.

More Oracle CVEs

Sources