CVE-2026-22018 is a denial-of-service vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition that affects multiple supported versions including Java SE 8, 11, 17, 21, 25, and 26. The vulnerability exists in the Libraries component and can be exploited remotely over network protocols without authentication or user interaction. The vulnerability presents a low severity risk with a CVSS score of 3.7, requiring high attack complexity to exploit. While the attack vector is network-accessible and requires no user interaction, the impact is limited to partial denial-of-service conditions affecting availability only, with no impact on confidentiality or integrity. The vulnerability can be exploited through APIs in the Libraries component, including web services that supply data to those APIs. There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.00039 indicates extremely low probability of exploitation, suggesting minimal community attention and no publicly available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:-:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:enterprise_performance_pack:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481_b50:*:*:-:*:*:* | ||
11.0.30CPE matchmatch criteria | cpe:2.3:a:oracle:jre:11.0.30:*:*:*:*:*:*:* | ||
17.0.18CPE matchmatch criteria | cpe:2.3:a:oracle:jre:17.0.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenJDK 26 vulnerabilities
May 28, 2026OpenJDK 25 vulnerabilities
May 28, 2026CRaC JDK 25 vulnerabilities
May 28, 2026CRaC JDK 21 vulnerabilities
May 28, 2026CRaC JDK 17 vulnerabilities
May 28, 2026OpenJDK 11 vulnerabilities
May 28, 2026OpenJDK 8 vulnerabilities
May 28, 2026