
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21945 is a denial-of-service vulnerability in the Security component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, caused by improper certificate validation during AIA (Authority Information Access) processing in TLS handshakes. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1; Oracle GraalVM for JDK 17.0.17 and 21.0.9; and Oracle GraalVM Enterprise Edition 21.3.16. It carries a CVSS v3.1 base score of 7.5 (High) (Oracle CPU Jan 2026, Red Hat Bugzilla).
The vulnerability is classified under CWE-295 (Improper Certificate Validation) and CWE-400 (Uncontrolled Resource Consumption). When AIA is enabled, a client can present its leaf certificate without the full chain of intermediate certificates, forcing the JVM to fetch certificate chain information via AIA URIs. Because there is no mechanism to verify that the provided URI points to a legitimate source, a remote attacker can craft a scenario that causes the JVM to make uncontrolled outbound requests (an SSRF-like behavior) or consume excessive resources during certificate chain resolution, resulting in a hang or repeatable crash. The vulnerability is exploitable over multiple network protocols without authentication or user interaction, and applies specifically to Java deployments that load and run untrusted code (e.g., sandboxed Java Web Start applications or applets); server deployments running only trusted code are at lower practical risk (Red Hat Bugzilla, Oracle CPU Jan 2026). Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).
Successful exploitation results in a complete denial of service — specifically, a hang or frequently repeatable crash of the affected Java SE, GraalVM for JDK, or GraalVM Enterprise Edition instance. There is no confidentiality or integrity impact; the vulnerability is limited to availability. The scope is unchanged, meaning the impact is confined to the vulnerable component itself. Client-side deployments running untrusted code (Web Start applications, applets) are most at risk, while server deployments running only administrator-installed trusted code face significantly lower practical exposure (Oracle CPU Jan 2026).
CertPathValidatorException or similar SSL/TLS errors.Oracle released fixed versions as part of the January 2026 Critical Patch Update: Java SE 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, and 25.0.2; GraalVM for JDK 17.0.18 and 21.0.10; GraalVM Enterprise Edition 21.3.17 (Red Hat Bugzilla, Oracle CPU Apr 2026). Red Hat addressed the issue via RHSA-2026:0849, RHSA-2026:0931, and RHSA-2026:4832. IBM has released patches for affected products including IBM i, IBM SDK Java Technology Edition, IBM MQ, IBM Business Automation Workflow, and others (IBM Advisory). Organizations should prioritize upgrading client-side Java deployments running untrusted code; server deployments running only trusted code face lower risk but should still be patched. As a temporary measure, disabling AIA fetching or restricting outbound network access from Java processes can reduce exposure.
Tenable published a blog post specifically highlighting this vulnerability, describing it as an SSRF vulnerability in Java TLS handshakes that creates a DoS risk, which drew notable attention from the security community (Tenable Blog). The vulnerability was also covered in Tenable's broader Oracle January 2026 CPU analysis covering 158 CVEs. Social media activity on Mastodon and Bluesky noted the disclosure shortly after the January 20, 2026 release. Multiple Linux distribution security teams (Red Hat, Debian, Ubuntu, SUSE, AlmaLinux, Rocky Linux) issued advisories and patches in the weeks following disclosure, reflecting broad ecosystem impact.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."