CVE-2026-83357
—Unauthenticated Takeover via HTTP in Oracle GraalVM Compiler (CVE-2026-83357)
CVE-2026-83357 is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM for JDK and Oracle GraalVM that allows an unauthenticated attacker with network access via HTTP to compromise the affected runtime. A successful attack can result in a complete takeover of Oracle GraalVM, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The specific affected releases are Oracle GraalVM for JDK 17 version 23.0.13.1, Oracle GraalVM for JDK 21 version 23.1.12.1, and Oracle GraalVM version 25.0.4.1, meaning applications built with or running on these exact builds are in scope. Because the attack surface requires network-reachable HTTP endpoints in applications using these GraalVM builds, exposure is limited to deployed services rather than developer workstations alone. As of this writing, the flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.
What to do: Apply Oracle's Critical Patch Update and move any GraalVM for JDK 17 (23.0.13.1), GraalVM for JDK 21 (23.1.12.1), or GraalVM 25.0.4.1 installations to the fixed successor releases for those tracks. Audit CI/CD pipelines, Docker base images, and build toolchains for these exact GraalVM versions, prioritizing services that expose HTTP endpoints to untrusted networks. Since the flaw is difficult to exploit and requires no authentication but high attack complexity, no emergency action beyond patching is indicated unless you find affected builds fronting public-facing services.
| Oracle GraalVM for JDK 17 (Oracle Java SE) | 23.0.13.1 |
| Oracle GraalVM for JDK 21 (Oracle Java SE) | 23.1.12.1 |
| Oracle GraalVM (Oracle Java SE) | 25.0.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.