Thomas Beckers discovered that the JAXP component of OpenJDK 25 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. (CVE-2026-22016) It was discovered that the Networking component of OpenJDK 25 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-34282) It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22021) It was discovered that the JGSS component of OpenJDK 25 did not correctly authenticate certain APIs. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-22013) It was discovered that the 2D component of OpenJDK 25 did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to obtain sensitive information. (CVE-2026-23865) It was discovered that the Libraries component of OpenJDK 25 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to modify data. (CVE-2026-22008) It was discovered that the Libraries component of OpenJDK 25 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22018) Ken Pyle discovered that the Security component of OpenJDK 25 did not correctly authenticate certain APIs. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-22007, CVE-2026-34268) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2026-04-21
Multiple critical vulnerabilities in OpenJDK 25, primarily involving insufficient API authentication across components like JAXP, Networking, JSSE, JGSS, Libraries, and Security, allow remote unauthenticated attackers to cause denial of service, obtain sensitive information, or modify data, with one local information disclosure flaw. Based on NVD data, affected Oracle JRE versions include 1.8.0, 11.0.30, 17.0.18, 21.0.10, and 25.0.2, with CVSS scores ranging to 7.5 (HIGH). The advisory includes security fixes, bug fixes, and new features; administrators should consult the OpenJDK vulnerability advisory for specific patching guidance.