OESA-2026-3818

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3818
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3818.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3818
Upstream
  • CVE-2026-22007
  • CVE-2026-22008
  • CVE-2026-22013
  • CVE-2026-22016
  • CVE-2026-22018
  • CVE-2026-26740
  • CVE-2026-34268
  • CVE-2026-46917
  • CVE-2026-46968
  • CVE-2026-47010
  • CVE-2026-47021
  • CVE-2026-47027
  • CVE-2026-47057
  • CVE-2026-47058
  • CVE-2026-47059
  • CVE-2026-47063
Published
2026-09-14T16:34:41Z
Modified
2026-09-13T16:57:26Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
openjdk-11 security update
Details

The OpenJDK runtime environment.

Security Fix(es):

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive(CVE-2025-28162)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.(CVE-2025-53057)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).(CVE-2025-53066)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 21.0.8 and 25; Oracle GraalVM for JDK: 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).(CVE-2025-61748)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).(CVE-2026-21925)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).(CVE-2026-21932)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).(CVE-2026-21933)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).(CVE-2026-21945)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 2.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).(CVE-2026-22007)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 2.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).(CVE-2026-22007)

Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).(CVE-2026-22008)

Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).(CVE-2026-22008)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).(CVE-2026-22013)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).(CVE-2026-22016)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).(CVE-2026-22018)

zlib versions up to and including 1.3.1.2 contain a global buffer overflow in the untgz utility. The vulnerability resides in the TGZfname() function, which copies an attacker-supplied archive name from the command-line argument (argv[]) into a fixed-size 1024-byte static global buffer using an unbounded strcpy() call without length validation. Supplying an archive name longer than 1024 bytes results in an out-of-bounds write that can lead to memory corruption, denial of service, and potentially code execution depending on compiler, build flags, architecture, and memory layout. The overflow occurs prior to any archive parsing or validation.(CVE-2026-22184)

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.(CVE-2026-22693)

A buffer overflow vulnerability (CWE-120) exists in giflib version 5.2.2. The vulnerability originates from the EGifGCBToExtension function, which fails to validate that the size of the input buffer is less than the size of the output buffer when processing a specially crafted Graphics Control Extension (GCE) block. This leads to overwriting an existing allocated GCE block. A remote attacker can exploit this vulnerability to cause a denial of service (DoS) and potentially affect the confidentiality, integrity, and availability of the system. Proof-of-concept (PoC) code has been publicly disclosed on GitHub.(CVE-2026-26740)

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.(CVE-2026-27171)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 2.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).(CVE-2026-34268)

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.(CVE-2026-41254)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).(CVE-2026-46917)

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).(CVE-2026-46968)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).(CVE-2026-47010)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).(CVE-2026-47021)

Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).(CVE-2026-47027)

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).(CVE-2026-47057)

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).(CVE-2026-47058)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).(CVE-2026-47059)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).(CVE-2026-47063)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4
openjdk-11

Package

Name
openjdk-11
Purl
pkg:rpm/openEuler/openjdk-11&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
java-11-openjdk-11.0.32.9-1.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "java-11-openjdk-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2003sp4.aarch64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2003sp4.aarch64.rpm"
    ],
    "src": [
        "java-11-openjdk-11.0.32.9-1.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "java-11-openjdk-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2003sp4.x86_64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3818.json"
openEuler:22.03-LTS-SP4
openjdk-11

Package

Name
openjdk-11
Purl
pkg:rpm/openEuler/openjdk-11&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
java-11-openjdk-11.0.32.9-1.oe2203sp4

Ecosystem specific

{
    "aarch64": [
        "java-11-openjdk-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2203sp4.aarch64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2203sp4.aarch64.rpm"
    ],
    "src": [
        "java-11-openjdk-11.0.32.9-1.oe2203sp4.src.rpm"
    ],
    "x86_64": [
        "java-11-openjdk-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2203sp4.x86_64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2203sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3818.json"
openEuler:24.03-LTS-SP1
openjdk-11

Package

Name
openjdk-11
Purl
pkg:rpm/openEuler/openjdk-11&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
java-11-openjdk-11.0.32.9-1.oe2403sp1

Ecosystem specific

{
    "aarch64": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2403sp1.aarch64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2403sp1.aarch64.rpm"
    ],
    "src": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp1.src.rpm"
    ],
    "x86_64": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2403sp1.x86_64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2403sp1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3818.json"
openEuler:24.03-LTS-SP3
openjdk-11

Package

Name
openjdk-11
Purl
pkg:rpm/openEuler/openjdk-11&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
java-11-openjdk-11.0.32.9-1.oe2403sp3

Ecosystem specific

{
    "aarch64": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2403sp3.aarch64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2403sp3.aarch64.rpm"
    ],
    "src": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp3.src.rpm"
    ],
    "x86_64": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2403sp3.x86_64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3818.json"
openEuler:24.03-LTS-SP4
openjdk-11

Package

Name
openjdk-11
Purl
pkg:rpm/openEuler/openjdk-11&distro=openEuler-24.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
java-11-openjdk-11.0.32.9-1.oe2403sp4

Ecosystem specific

{
    "aarch64": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2403sp4.aarch64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2403sp4.aarch64.rpm"
    ],
    "src": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp4.src.rpm"
    ],
    "x86_64": [
        "java-11-openjdk-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-debuginfo-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-debugsource-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-demo-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-demo-slowdebug-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-devel-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-devel-slowdebug-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-headless-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-headless-slowdebug-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-javadoc-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-javadoc-zip-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-jmods-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-jmods-slowdebug-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-slowdebug-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-src-11.0.32.9-1.oe2403sp4.x86_64.rpm",
        "java-11-openjdk-src-slowdebug-11.0.32.9-1.oe2403sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3818.json"