USN-8796-1: OpenJDK 21 vulnerabilities
OpenJDK 21 reveals three authentication vulnerabilities that could lead to sensitive information leakage or denial of service.
OpenJDK 21 exposes multiple authentication-related vulnerabilities (CVE-2026-61308, CVE-2026-70907, CVE-2026-60589), where remote attackers could potentially leak sensitive information or cause a denial of service.
- OpenJDK 21 contains three security vulnerabilities related to user authentication and potential information leakage or denial of service.
Vulnerabilities mentionedAll →
- CVE-2026-613086.8<1%Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (componentpublished +2 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-61308+2 related CVEs |
Kai Aizen discovered that the Networking component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-61308) It was discovered that the JSSE component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-70907) It was discovered that the Security component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-60589)
This source does not provide full text. Read it at ubuntu.com.