
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21933 is a CRLF injection vulnerability in the Networking component (specifically the HttpServer request handling) of Oracle Java SE that allows a remote, unauthenticated attacker to bypass security controls and perform unauthorized data operations. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. Affected versions include Oracle JDK/JRE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1, as well as Oracle GraalVM Enterprise Edition 21.3.16 and GraalVM for JDK 17.0.17 and 21.0.9. It carries a CVSS v3.1 base score of 6.1 (Medium) (Oracle CPU Jan 2026, Red Hat Bugzilla).
The vulnerability is classified as CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection) and resides in the HttpServer component of the Java SE Networking library. An attacker can inject carriage return and line feed characters (\r\n) into HTTP responses served by the built-in Java HttpServer, potentially manipulating HTTP headers and enabling cross-site scripting (XSS) attacks against users of applications that rely on this server. Exploitation requires network access and user interaction (e.g., a victim visiting a crafted URL or interacting with a malicious response), and no authentication is required. The scope is changed, meaning the impact can extend beyond the vulnerable component itself. Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla, Oracle CPU Jan 2026).
Successful exploitation can lead to low-level confidentiality and integrity impacts with no availability impact, consistent with the CVSS score. The changed scope indicates that a successful attack can affect components beyond the Java runtime itself — most notably, web browsers or other clients interacting with applications using the vulnerable HttpServer. The primary risk is HTTP response splitting leading to XSS, which could allow session hijacking, credential theft, or injection of malicious content into user sessions (Oracle CPU Jan 2026, Red Hat Bugzilla).
com.sun.net.httpserver.HttpServer (or HttpsServer) class, particularly those exposing HTTP endpoints to external users, running affected Java SE versions (8u471, 11.0.29, 17.0.17, 21.0.9, or 25.0.1).%0d%0a or \r\n) in a parameter or header field that the server reflects back in its HTTP response headers.Set-Cookie, Location) or inject a second HTTP response body.Content-Type header and body, the attacker can cause the victim's browser to interpret attacker-controlled content as HTML/JavaScript, enabling XSS attacks such as session cookie theft or phishing page injection.HttpServer-based endpoints containing URL-encoded CRLF sequences (%0d%0a, %0D%0A) in query parameters or headers; HTTP responses with unexpected additional headers or split response bodies.%0d, %0a, or \r\n patterns in parameter values; unexpected Set-Cookie or Location headers in server responses not set by application logic.Oracle has released fixed versions addressing CVE-2026-21933: Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, and 25.0.2. Organizations should upgrade to these patched releases as the primary remediation. Red Hat has issued corresponding errata (RHSA-2026:0849, RHSA-2026:0931, RHSA-2026:4832) for affected RHEL and OpenJDK ELS packages. IBM has also released patches for affected products including IBM i, IBM MQ, IBM Cloud Pak for Business Automation, and numerous other IBM Java SDK-based products. As a temporary workaround, Oracle recommends blocking network protocols required by the attack where feasible, though upgrading is strongly preferred (Oracle CPU Jan 2026, Red Hat Bugzilla, IBM i Advisory).
The vulnerability received standard industry attention as part of Oracle's January 2026 CPU, which addressed 337 security patches across Oracle product families. Red Hat promptly issued errata for affected OpenJDK packages within days of the Oracle advisory. IBM issued a broad set of security bulletins across dozens of affected products over the following months. The OpenJDK project published upstream fix commits for all affected branches (8, 11, 17, 21, 25). No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond routine patch tracking (Oracle CPU Jan 2026, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."