OpenJDK: Enhance TLS server (2026-08 Security Update)
Published Aug 18, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.28%
Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected products
- Vendor Oracle Corporation Product Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Defaultn/a
- Version Oracle GraalVM Enterprise Edition:21.3.19StatusaffectedConstraints-
- Version Oracle GraalVM for JDK:17.0.20StatusaffectedConstraints-
- Version Oracle GraalVM for JDK:21.0.12StatusaffectedConstraints-
- Version Oracle Java SE:11.0.32StatusaffectedConstraints-
- Version Oracle Java SE:17.0.20StatusaffectedConstraints-
- Version Oracle Java SE:21.0.12StatusaffectedConstraints-
- Version Oracle Java SE:25.0.4StatusaffectedConstraints-
- Version Oracle Java SE:26.0.2StatusaffectedConstraints-
- Version Oracle Java SE:8u501StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | n/a |
|
No data.
No data.
Red Hat Enterprise Linux 10
java-21-openjdk-1:21.0.12.1.1-1.2.el10
Fixed · RHSA-2026:55787
Red Hat Enterprise Linux 10
java-25-openjdk-1:25.0.4.1.1-1.1.el10
Fixed · RHSA-2026:55798
Red Hat Enterprise Linux 10.0 Extended Update Support
java-21-openjdk-1:21.0.12.1.1-1.1.el10
Fixed · RHSA-2026:55787
Red Hat Enterprise Linux 7 Extended Lifecycle Support
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9
Fixed · RHSA-2026:55774
Red Hat Enterprise Linux 8
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 8
java-21-openjdk-1:21.0.12.1.1-1.1.el8
Fixed · RHSA-2026:55787
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
java-17-openjdk-1:17.0.20.1.1-1.1.el8
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 9
java-1.8.0-openjdk-1:1.8.0.504.b01-1.2.el9
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 9
java-17-openjdk-1:17.0.20.1.1-1.2.el9
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 9
java-21-openjdk-1:21.0.12.1.1-1.2.el9
Fixed · RHSA-2026:55787
Red Hat Enterprise Linux 9
java-25-openjdk-1:25.0.4.1.1-1.1.el9
Fixed · RHSA-2026:55798
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
java-17-openjdk-1:17.0.20.1.1-1.1.el9
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
java-17-openjdk-1:17.0.20.1.1-1.1.el9
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
java-21-openjdk-1:21.0.12.1.1-1.1.el9
Fixed · RHSA-2026:55787
Red Hat Enterprise Linux 9.6 Extended Update Support
java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9
Fixed · RHSA-2026:55775
Red Hat Enterprise Linux 9.6 Extended Update Support
java-17-openjdk-1:17.0.20.1.1-1.1.el9
Fixed · RHSA-2026:55781
Red Hat Enterprise Linux 9.6 Extended Update Support
java-21-openjdk-1:21.0.12.1.1-1.1.el9
Fixed · RHSA-2026:55787
Red Hat Hardened Images
java-21-openjdk-main-21.0.12.1.1-1.0.hum1
Fixed · RHSA-2026:58266
Red Hat Hardened Images
java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1
Fixed · RHSA-2026:57175
Red Hat Hardened Images
java-25-openjdk-main-25.0.4.1.1-1.1.hum1
Fixed · RHSA-2026:57765
Red Hat Hardened Images
java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1
Fixed · RHSA-2026:57177
Red Hat OpenJDK 11 els for RHEL 7
java-11-openjdk-1:11.0.32.1.1-1.el7_9
Fixed · RHSA-2026:55778
Red Hat OpenJDK 11 els for RHEL 8
java-11-openjdk-1:11.0.32.1.1-1.el8
Fixed · RHSA-2026:55778
Red Hat OpenJDK 11 els for RHEL 9
java-11-openjdk-1:11.0.32.1.1-1.el9
Fixed · RHSA-2026:55778
Exploit Intelligence
exploit-intelligence-tech-preview/vulnerability-analysis-rhel9
Out of support scope
Red Hat Enterprise Linux 10
java-21-ibm-semeru-certified-jdk
Affected
Red Hat Enterprise Linux 6
java-1.6.0-openjdk
Out of support scope
Red Hat Enterprise Linux 6
java-1.7.0-openjdk
Out of support scope
Red Hat Enterprise Linux 6
java-1.8.0-openjdk
Out of support scope
Red Hat Enterprise Linux 7
java-1.6.0-openjdk
Out of support scope
Red Hat Enterprise Linux 7
java-1.7.0-openjdk
Out of support scope
Red Hat Enterprise Linux 8
java-1.8.0-ibm
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | java-21-openjdk-1:21.0.12.1.1-1.2.el10 | Fixed | RHSA-2026:55787 |
| Red Hat Enterprise Linux 10 | java-25-openjdk-1:25.0.4.1.1-1.1.el10 | Fixed | RHSA-2026:55798 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | java-21-openjdk-1:21.0.12.1.1-1.1.el10 | Fixed | RHSA-2026:55787 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9 | Fixed | RHSA-2026:55774 |
| Red Hat Enterprise Linux 8 | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8 | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 8 | java-21-openjdk-1:21.0.12.1.1-1.1.el8 | Fixed | RHSA-2026:55787 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | java-17-openjdk-1:17.0.20.1.1-1.1.el8 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 9 | java-1.8.0-openjdk-1:1.8.0.504.b01-1.2.el9 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 9 | java-17-openjdk-1:17.0.20.1.1-1.2.el9 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 9 | java-21-openjdk-1:21.0.12.1.1-1.2.el9 | Fixed | RHSA-2026:55787 |
| Red Hat Enterprise Linux 9 | java-25-openjdk-1:25.0.4.1.1-1.1.el9 | Fixed | RHSA-2026:55798 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | java-17-openjdk-1:17.0.20.1.1-1.1.el9 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | java-17-openjdk-1:17.0.20.1.1-1.1.el9 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | java-21-openjdk-1:21.0.12.1.1-1.1.el9 | Fixed | RHSA-2026:55787 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9 | Fixed | RHSA-2026:55775 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | java-17-openjdk-1:17.0.20.1.1-1.1.el9 | Fixed | RHSA-2026:55781 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | java-21-openjdk-1:21.0.12.1.1-1.1.el9 | Fixed | RHSA-2026:55787 |
| Red Hat Hardened Images | java-21-openjdk-main-21.0.12.1.1-1.0.hum1 | Fixed | RHSA-2026:58266 |
| Red Hat Hardened Images | java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1 | Fixed | RHSA-2026:57175 |
| Red Hat Hardened Images | java-25-openjdk-main-25.0.4.1.1-1.1.hum1 | Fixed | RHSA-2026:57765 |
| Red Hat Hardened Images | java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1 | Fixed | RHSA-2026:57177 |
| Red Hat OpenJDK 11 els for RHEL 7 | java-11-openjdk-1:11.0.32.1.1-1.el7_9 | Fixed | RHSA-2026:55778 |
| Red Hat OpenJDK 11 els for RHEL 8 | java-11-openjdk-1:11.0.32.1.1-1.el8 | Fixed | RHSA-2026:55778 |
| Red Hat OpenJDK 11 els for RHEL 9 | java-11-openjdk-1:11.0.32.1.1-1.el9 | Fixed | RHSA-2026:55778 |
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Out of support scope | n/a |
| Red Hat Enterprise Linux 10 | java-21-ibm-semeru-certified-jdk | Affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | java-1.8.0-openjdk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | java-1.6.0-openjdk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | java-1.7.0-openjdk | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-70907 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2513038 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-61856 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-70907
- https://www.cve.org/CVERecord?id=CVE-2026-70907
- https://www.oracle.com/security-alerts/cspuaug2026.html vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-70907 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2513038 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-61856 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-70907 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-70907 | ||
| https://www.oracle.com/security-alerts/cspuaug2026.html | vendor-advisory |
Change history (0)
No recorded changes yet.