CVE-2026-22018
Amazon Corretto JDK vulnerability analysis and mitigation

Overview

CVE-2026-22018 is a denial-of-service vulnerability in the Libraries component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's April 2026 Critical Patch Update. The root cause is missing validation of ZIP64 content in ZIP files, which can lead to out-of-bounds reads. Affected versions include Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. It carries a CVSS v3.1 base score of 3.7 (Low) (Oracle CPU Apr 2026, Github Advisory).

Technical details

The vulnerability is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-125 (Out-of-bounds Read), stemming from insufficient validation of ZIP64 metadata within ZIP files processed by the Java Libraries component (Red Hat Bugzilla). An unauthenticated remote attacker can exploit this flaw by supplying a maliciously crafted ZIP file via any supported network protocol to an API or web service that processes ZIP content, triggering an out-of-bounds read condition. Exploitation requires high attack complexity (AC:H), meaning specific conditions must be met, but no privileges or user interaction are required. The vulnerability also applies to sandboxed Java Web Start applications and Java applets that load untrusted code from the internet (Oracle CPU Apr 2026). Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).

Impact

Successful exploitation results in a partial denial of service (partial DOS) affecting the availability of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition installations. There is no impact on confidentiality or integrity — the vulnerability is limited to availability, with a low availability impact rating. The scope is unchanged, meaning the impact is confined to the vulnerable component itself, with no potential for lateral movement or data exfiltration (Oracle CPU Apr 2026, Github Advisory). Downstream IBM products including IBM SDK Java Technology Edition, IBM Semeru Runtime, IBM Sterling Transformation Extender, IBM App Connect Enterprise, IBM InfoSphere Information Server, and IBM Voice Gateway are also affected (IBM Advisory).

Mitigation and workarounds

Oracle has released fixed versions as part of the April 2026 Critical Patch Update: Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, and 25.0.3 address this vulnerability (Red Hat Bugzilla). Organizations should upgrade all affected Java SE, GraalVM for JDK, and GraalVM Enterprise Edition installations to the patched versions. IBM has released corresponding advisories and patches for affected downstream products including IBM Semeru Runtime, IBM SDK Java Technology Edition, and various IBM enterprise products (IBM Advisory). As a temporary measure, network segmentation to limit exposure of Java-based services to untrusted networks may reduce risk, though upgrading is the recommended long-term solution (Oracle CPU Apr 2026). Organizations running Java Web Start applications or applets that load untrusted code should prioritize patching.

Community reactions

Red Hat tracked this vulnerability via Bugzilla and issued errata RHSA-2026:22139 for Red Hat Enterprise Linux 8, as well as multiple additional errata (RHSA-2026:9254, RHSA-2026:9255, RHSA-2026:9690, RHSA-2026:9693, RHSA-2026:9694, RHSA-2026:11403, RHSA-2026:11822, RHSA-2026:22139) covering various OpenJDK versions (Red Hat Bugzilla). SUSE, Debian, Ubuntu, Amazon Linux, AlmaLinux, Rocky Linux, and openSUSE have all issued security advisories and updates for their respective OpenJDK packages. IBM published multiple security bulletins covering a broad range of affected products. The vulnerability received routine coverage consistent with a quarterly Oracle CPU patch cycle, with no notable controversy or elevated community concern given its low severity rating.

Additional resources


SourceThis report was generated using AI

Related Amazon Corretto JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34282HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-amazon-corretto-devel
NoYesApr 21, 2026
CVE-2026-22016HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-ibm-devel
NoYesApr 21, 2026
CVE-2026-22021MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.7.0-openjdk-demo
NoYesApr 21, 2026
CVE-2026-22018LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-headless
NoYesApr 21, 2026
CVE-2026-34268LOW2.9
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-demo
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management