Thomas Beckers discovered that the JAXP component of CRaC JDK 17 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. (CVE-2026-22016) It was discovered that the Networking component of CRaC JDK 17 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-34282) It was discovered that the JSSE component of CRaC JDK 17 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22021) It was discovered that the JGSS component of CRaC JDK 17 did not correctly authenticate certain APIs. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-22013) It was discovered that the 2D component of CRaC JDK 17 did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to leak sensitive information. (CVE-2026-23865) It was discovered that the Libraries component of CRaC JDK 17 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22018) Ken Pyle discovered that the Security component of CRaC JDK 17 did not correctly authenticate certain APIs. A local attacker could possibly use this issue to leak sensitive information. (CVE-2026-22007, CVE-2026-34268) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2026-04-21
Multiple vulnerabilities in CRaC JDK 17, including API authentication flaws in JAXP, Networking, JSSE, JGSS, Libraries, and Security components, allow remote attackers to cause denial of service or information disclosure, while an integer handling flaw in the 2D component could leak data via a crafted file. The NVD data indicates these CVEs also affect Oracle JRE versions 1.8.0, 11.0.30, and 17.0.18, with CVSS scores ranging from 5.3 to 7.5. The article advises reviewing the linked OpenJDK advisory for specific fixed versions, bug fixes, and potential incompatible changes introduced in the update.