OVERVIEW CVE-2026-34282 is a denial-of-service vulnerability in Oracle Java SE's Networking component, affecting multiple versions including Java SE 8, 11, 17, 21, 25, and 26, as well as Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition. The vulnerability can be exploited through APIs in the Networking component, including web services that process untrusted data, and impacts both server deployments and client-side Java applications running through Java Web Start or applets. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The attack is easily exploitable and results in high availability impact, allowing attackers to cause either application hangs or repeated crashes leading to complete denial of service. No confidentiality or integrity impacts are associated with this vulnerability. EXPLOITATION STATUS The vulnerability is currently inactive on the Known Exploited Vulnerabilities (KEV) catalog with no evidence of active exploitation in the wild. No public exploit code is currently available, and the extremely low EPSS score of 0.0004 indicates minimal real-world exploitation probability. The moderate FAUCET Risk Score of 47 suggests the vulnerability warrants attention despite low current community activity, particularly given the broad range of affected Java versions and deployment scenarios.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:enterprise_performance_pack:*:*:* | ||
11.0.30CPE matchmatch criteria | cpe:2.3:a:oracle:jre:11.0.30:*:*:*:*:*:*:* | ||
17.0.18CPE matchmatch criteria | cpe:2.3:a:oracle:jre:17.0.18:*:*:*:*:*:*:* | ||
21.0.10CPE matchmatch criteria | cpe:2.3:a:oracle:jre:21.0.10:*:*:*:*:*:*:* | ||
25.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:jre:25.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenJDK 26 vulnerabilities
May 28, 2026OpenJDK 25 vulnerabilities
May 28, 2026CRaC JDK 25 vulnerabilities
May 28, 2026CRaC JDK 21 vulnerabilities
May 28, 2026CRaC JDK 17 vulnerabilities
May 28, 2026OpenJDK 11 vulnerabilities
May 28, 2026