CVE-2026-22013 is a vulnerability in the Java GSSAPI (JGSS) component affecting Oracle Java SE versions 8u481 through 26, Oracle GraalVM for JDK (versions 17.0.18 and 21.0.10), and Oracle GraalVM Enterprise Edition 21.3.17. The vulnerability specifically targets client-side Java deployments such as Java Web Start applications and applets that execute untrusted code from the internet. The vulnerability has a CVSS 3.1 base score of 5.3 (Medium severity) with a network attack vector requiring high complexity and user interaction. An unauthenticated attacker with network access could potentially compromise confidentiality and gain unauthorized access to critical data, though no integrity or availability impacts are expected. The high complexity and requirement for user involvement significantly limit exploitability compared to other vulnerabilities. This vulnerability is not currently being actively exploited in the wild, with an EPSS score of 0.0004 indicating very low probability of exploitation. No public exploit code is available, and the vulnerability has not been included in the CISA Known Exploited Vulnerabilities catalog. Community attention remains minimal given the stringent prerequisites and low technical severity rating, suggesting organizations can prioritize patching based on their reliance on vulnerable client-side Java deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update481:*:*:-:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update481:*:*:enterprise_performance_pack:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update481_b50:*:*:-:*:*:* | ||
11.0.30CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.30:*:*:*:*:*:*:* | ||
17.0.18CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:17.0.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenJDK 26 vulnerabilities
May 28, 2026OpenJDK 25 vulnerabilities
May 28, 2026CRaC JDK 25 vulnerabilities
May 28, 2026CRaC JDK 21 vulnerabilities
May 28, 2026CRaC JDK 17 vulnerabilities
May 28, 2026OpenJDK 11 vulnerabilities
May 28, 2026OpenJDK 8 vulnerabilities
May 28, 2026