CVE-2026-22016
Amazon Corretto JDK vulnerability analysis and mitigation

Overview

CVE-2026-22016 is a vulnerability in the JAXP (Java API for XML Processing) component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's April 2026 Critical Patch Update. The flaw allows unauthenticated remote attackers to gain unauthorized access to critical data accessible by the affected Java runtime. Affected versions include Oracle Java SE 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26; Oracle GraalVM for JDK 17.0.18 and 21.0.10; and Oracle GraalVM Enterprise Edition 21.3.17. It was published on April 21, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Oracle CPU Apr 2026, Github Advisory).

Technical details

The root cause of CVE-2026-22016 is that XPath.compile creates a new XPathExpression where the XML security manager (xmlSecMgr) is null, leaving the JAXP component open to XML External Entity (XXE) and XML Entity Expansion (XEE) attacks (CWE-611, CWE-200) (Red Hat Bugzilla). The vulnerability is exploitable over the network via multiple protocols without authentication or user interaction, and can be triggered through web services that supply data to JAXP APIs, or through sandboxed Java Web Start applications and Java applets that load untrusted code from the internet (Oracle CPU Apr 2026). The vulnerability was reported to Oracle by Thomas Beckers of Soptim (Oracle CPU Apr 2026). Upstream OpenJDK commits addressing the flaw are publicly available for versions 8, 11, 17, 21, and 25 (Red Hat Bugzilla).

Impact

Successful exploitation results in high confidentiality impact — an unauthenticated attacker can gain complete unauthorized access to all data accessible by the affected Oracle Java SE, GraalVM for JDK, or GraalVM Enterprise Edition instance. There is no integrity or availability impact. The vulnerability is particularly concerning in server-side deployments where Java web services process XML from untrusted sources, as well as in client-side environments running sandboxed Java Web Start applications or applets. Downstream IBM products including IBM Semeru Runtime, IBM SDK Java Technology Edition, IBM App Connect Enterprise, IBM InfoSphere Information Server, IBM Sterling Transformation Extender, and others are also affected (Oracle CPU Apr 2026, Github Advisory).

Mitigation and workarounds

Oracle has released fixed versions as part of the April 2026 Critical Patch Update: Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, and 25.0.3 address this vulnerability (Red Hat Bugzilla). Downstream vendors including Red Hat (RHSA-2026:9254, RHSA-2026:9255, RHSA-2026:22139, RHSA-2026:22328), IBM, SUSE, Debian, Ubuntu, and Amazon Linux have also released updated packages. Organizations should prioritize upgrading all affected Java SE and GraalVM installations to patched versions. As a temporary measure, restricting network access to services that process XML via JAXP APIs and disabling untrusted XML input sources can reduce exposure (Oracle CPU Apr 2026).

Community reactions

The vulnerability received standard coverage from security aggregators and Linux distribution security teams, with patch advisories issued by Red Hat, SUSE, Debian, Ubuntu, Amazon Linux, and IBM shortly after Oracle's April 2026 CPU release. Azul Systems published a blog post highlighting the importance of applying Java runtime security updates promptly (Oracle CPU Apr 2026). No notable independent researcher commentary or significant social media discussion beyond routine CVE alert posts has been observed.

Additional resources


SourceThis report was generated using AI

Related Amazon Corretto JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34282HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-amazon-corretto-devel
NoYesApr 21, 2026
CVE-2026-22016HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-ibm-devel
NoYesApr 21, 2026
CVE-2026-22021MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.7.0-openjdk-demo
NoYesApr 21, 2026
CVE-2026-22018LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-headless
NoYesApr 21, 2026
CVE-2026-34268LOW2.9
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-demo
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management