ZeroHour

CVE-2026-87287

niche

Unauthenticated HTTP Takeover Flaw in Oracle GraalVM 25.0.4.1 Compiler

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

Oracle GraalVM 25.0.4.1 (part of Oracle Java SE) contains a vulnerability in its Compiler component that allows an unauthenticated remote attacker with network access via HTTP to compromise the GraalVM installation. Oracle rates the vulnerability as difficult to exploit (Attack Complexity: High), but a successful attack can result in a complete takeover of GraalVM with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Only the specific version Oracle GraalVM 25.0.4.1 is listed as affected. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported. Because exploitation depends on HTTP-reachable GraalVM runtimes, deployments that do not expose GraalVM-based services to untrusted networks are at substantially lower risk.

What to do: Upgrade Oracle GraalVM from 25.0.4.1 to the fixed release provided in Oracle's latest Critical Patch Update, since only that version is listed as affected. Restrict HTTP/network access to GraalVM-based services so they are not reachable by untrusted clients, which also mitigates the high attack-complexity exploitation path. Audit logs on GraalVM 25.0.4.1 hosts for unexplained process or compiler activity until the upgrade is complete.

Affected
Oracle GraalVM (Oracle Java SE), Compiler component
Estimated exposure
nichelikely low tens of thousands of installations at most (single point release of a specialized JVM distribution) — GraalVM is a niche JDK/JVM distribution compared to standard Java installs, and only one specific point release (25.0.4.1) is affected, so the truly exposed population of HTTP-reachable instances is small; no public scan or install-count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.