CVE-2026-21945
Amazon Corretto JDK vulnerability analysis and mitigation

Overview

CVE-2026-21945 is a denial-of-service vulnerability in the Security component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, caused by improper certificate validation during AIA (Authority Information Access) processing in TLS handshakes. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1; Oracle GraalVM for JDK 17.0.17 and 21.0.9; and Oracle GraalVM Enterprise Edition 21.3.16. It carries a CVSS v3.1 base score of 7.5 (High) (Oracle CPU Jan 2026, Red Hat Bugzilla).

Technical details

The vulnerability is classified under CWE-295 (Improper Certificate Validation) and CWE-400 (Uncontrolled Resource Consumption). When AIA is enabled, a client can present its leaf certificate without the full chain of intermediate certificates, forcing the JVM to fetch certificate chain information via AIA URIs. Because there is no mechanism to verify that the provided URI points to a legitimate source, a remote attacker can craft a scenario that causes the JVM to make uncontrolled outbound requests (an SSRF-like behavior) or consume excessive resources during certificate chain resolution, resulting in a hang or repeatable crash. The vulnerability is exploitable over multiple network protocols without authentication or user interaction, and applies specifically to Java deployments that load and run untrusted code (e.g., sandboxed Java Web Start applications or applets); server deployments running only trusted code are at lower practical risk (Red Hat Bugzilla, Oracle CPU Jan 2026). Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).

Impact

Successful exploitation results in a complete denial of service — specifically, a hang or frequently repeatable crash of the affected Java SE, GraalVM for JDK, or GraalVM Enterprise Edition instance. There is no confidentiality or integrity impact; the vulnerability is limited to availability. The scope is unchanged, meaning the impact is confined to the vulnerable component itself. Client-side deployments running untrusted code (Web Start applications, applets) are most at risk, while server deployments running only administrator-installed trusted code face significantly lower practical exposure (Oracle CPU Jan 2026).

Exploitation steps

  1. Identify target: Locate a client-side Java deployment (e.g., Java Web Start application or Java applet) running a vulnerable version of Oracle Java SE (8u471, 11.0.29, 17.0.17, 21.0.9, or 25.0.1) or GraalVM for JDK (17.0.17, 21.0.9) with AIA certificate fetching enabled.
  2. Craft a malicious TLS server: Set up a TLS server that presents a leaf certificate containing an AIA extension pointing to an attacker-controlled or unreachable/slow URI for intermediate certificate retrieval.
  3. Induce connection: Cause the vulnerable Java client to initiate a TLS connection to the malicious server (e.g., by hosting a malicious applet or Web Start application that the victim loads).
  4. Trigger resource exhaustion: The Java client attempts to fetch the AIA URI to complete certificate chain validation. Because there is no validation that the URI is legitimate, the client may be directed to a resource that causes excessive resource consumption, resulting in a hang or crash of the JVM process.
  5. Achieve DoS: The Java application becomes unresponsive or crashes, completing the denial-of-service objective (Red Hat Bugzilla, Oracle CPU Jan 2026).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS connections from Java processes to unusual or external URIs during TLS handshake activity; connections to URIs embedded in certificate AIA extensions that resolve to attacker-controlled infrastructure.
  • Process: Java processes (java, javaw) becoming unresponsive or consuming abnormally high CPU/memory; repeated JVM crashes or OOM errors in client-side Java applications.
  • Logs: Java exception stack traces related to certificate chain validation failures or AIA URI fetch timeouts in application logs; repeated CertPathValidatorException or similar SSL/TLS errors.

Mitigation and workarounds

Oracle released fixed versions as part of the January 2026 Critical Patch Update: Java SE 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, and 25.0.2; GraalVM for JDK 17.0.18 and 21.0.10; GraalVM Enterprise Edition 21.3.17 (Red Hat Bugzilla, Oracle CPU Apr 2026). Red Hat addressed the issue via RHSA-2026:0849, RHSA-2026:0931, and RHSA-2026:4832. IBM has released patches for affected products including IBM i, IBM SDK Java Technology Edition, IBM MQ, IBM Business Automation Workflow, and others (IBM Advisory). Organizations should prioritize upgrading client-side Java deployments running untrusted code; server deployments running only trusted code face lower risk but should still be patched. As a temporary measure, disabling AIA fetching or restricting outbound network access from Java processes can reduce exposure.

Community reactions

Tenable published a blog post specifically highlighting this vulnerability, describing it as an SSRF vulnerability in Java TLS handshakes that creates a DoS risk, which drew notable attention from the security community (Tenable Blog). The vulnerability was also covered in Tenable's broader Oracle January 2026 CPU analysis covering 158 CVEs. Social media activity on Mastodon and Bluesky noted the disclosure shortly after the January 20, 2026 release. Multiple Linux distribution security teams (Red Hat, Debian, Ubuntu, SUSE, AlmaLinux, Rocky Linux) issued advisories and patches in the weeks following disclosure, reflecting broad ecosystem impact.

Additional resources


SourceThis report was generated using AI

Related Amazon Corretto JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34282HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • cpe:2.3:a:oracle:graalvm:*:*:*:*:enterprise:*:*:*
NoYesApr 21, 2026
CVE-2026-22016HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-headless
NoYesApr 21, 2026
CVE-2026-22021MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openj9-src
NoYesApr 21, 2026
CVE-2026-22018LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-devel-slowdebug-debuginfo
NoYesApr 21, 2026
CVE-2026-34268LOW2.9
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-fastdebug-debuginfo
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management