CVE-2026-47059
Analyzed Analyzed - Analysis Complete

Memory Corruption in Oracle Java SE

Vulnerability report for CVE-2026-47059, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-03

Assigner: Oracle

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-03
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
oracle jdk 1.8.0
oracle jdk 11.0.31
oracle jdk 17.0.19
oracle jdk 21.0.11
oracle jdk 25.0.3
oracle jdk 26.0.1
oracle jdk 1.8.0
oracle graalvm 21.3.18
oracle graalvm_for_jdk 17.0.19
oracle graalvm_for_jdk 21.0.11
oracle jre 1.8.0
oracle jre 11.0.31
oracle jre 17.0.19
oracle jre 21.0.11
oracle jre 25.0.3
oracle jre 26.0.1
oracle jre 1.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition affecting multiple versions. It allows an unauthenticated attacker with network access to cause a partial denial of service (DOS) in the affected products. The vulnerability is difficult to exploit and impacts the availability of the systems.

Detection Guidance

This vulnerability affects specific versions of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition. Detection involves checking installed versions against the affected releases (e.g., Java SE 8u491, 11.0.31, 17.0.19, etc.). Use commands like 'java -version' or 'where java' to identify installed versions. Compare these against the list of vulnerable versions provided in the CVE description.

Impact Analysis

If you use affected versions of Oracle Java SE, GraalVM for JDK, or GraalVM Enterprise Edition in client environments running untrusted code, an attacker could disrupt service availability. Servers running trusted code are not affected.

Compliance Impact

This vulnerability causes a partial denial of service in affected Java deployments, which could disrupt system availability. For GDPR, availability impacts may affect data processing operations requiring uninterrupted access. HIPAA requires safeguards for data availability, so disruptions could pose compliance risks if critical systems are affected.

Mitigation Strategies

Update affected Java versions to the latest patched releases. For Oracle Java SE, upgrade to versions beyond those listed as vulnerable (8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1). Disable Java Web Start applications and sandboxed Java applets if not required. Restrict network access to Java applications where possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47059. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart