Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal
Published Jul 8, 2026
8.8
HIGHCVSS 3.1
EPSS 0.18%
Description
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
Affected products
-
- Version 0StatusaffectedConstraints<3.70+nmu1ubuntu1.22.04.1
- Version 0StatusaffectedConstraints<3.70+nmu1ubuntu1.24.04.1
- Version 0StatusaffectedConstraints<3.74ubuntu1.1
- Version 0StatusaffectedConstraints<3.75ubuntu1.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Hardened Images
java-21-openjdk
Not affected
Red Hat Hardened Images
java-25-openjdk
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | java-21-openjdk | Not affected | n/a |
| Red Hat Hardened Images | java-25-openjdk | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat products are not affected by this vulnerability. CVE-2026-10037 is a packaging defect specific to Debian/Ubuntu OpenJDK distributions: those distributions ship a desktop MIME handler that, via cautious-launcher and the mailcap application/x-java-archive association, can auto-execute a downloaded .jar file. The fix was delivered in the mailcap package (USN-8518-1), not in OpenJDK source code. Red Hat's OpenJDK RPMs ship only jconsole.desktop, which declares no MimeType and no .jar association, do not depend on or install mailcap, and register no application/x-java-archive handler. The vulnerable code path is therefore not present in any Red Hat OpenJDK build. This was independently confirmed downstream by the Hummingbird team, which resolved both trackers (HUM-3135, HUM-3136) as "Not a Bug / Vulnerable Code not Present."
Red Hat mitigation
No mitigation is required: Red Hat products are not affected. Red Hat's OpenJDK packages do not ship the .jar MIME handler, do not depend on the mailcap package, and register no application/x-java-archive association, so the vulnerable code path is not present. Users of Debian/Ubuntu OpenJDK should apply the upstream mailcap fix (USN-8518-1).
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jul 10, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.18% (0.00176) | 6.45th | v5 (v2026.06.15) |
| Jul 9, 2026 | 0.12% (0.00120) | 2.17th | v5 (v2026.06.15) |
References (5)
- https://access.redhat.com/security/cve/CVE-2026-10037 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/openjdk-25/+bug/2153100 issue-tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2498293 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-10037
- https://www.cve.org/CVERecord?id=CVE-2026-10037
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-10037 | Vendor Advisory | |
| https://bugs.launchpad.net/ubuntu/+source/openjdk-25/+bug/2153100 | issue-tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498293 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-10037 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-10037 |
Change history (0)
No recorded changes yet.