CVE-2026-47059
OpenJDK JDK vulnerability analysis and mitigation

Overview

CVE-2026-47059 is a vulnerability in the 2D component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's July 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. The vulnerability was reported by researcher BBBBear and published on July 21, 2026. It carries a CVSS v3.1 base score of 3.7 (Low severity) (Oracle CPU Jul 2026).

Technical details

The vulnerability resides in the 2D component of Oracle Java SE and related products, and is exploitable by an unauthenticated remote attacker via multiple network protocols. Exploitation requires high attack complexity, meaning specific conditions must be met, and no privileges or user interaction are required. The vulnerability specifically applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and execute untrusted code from the internet; server-side deployments running only trusted code are not affected. No CWE classification or detailed technical write-up has been publicly disclosed at this time (Oracle CPU Jul 2026).

Impact

Successful exploitation can result in a partial denial of service (partial DOS) affecting the availability of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. There is no impact to confidentiality or integrity. The scope of impact is limited to the affected Java runtime environment, and the vulnerability does not enable code execution, data exfiltration, or lateral movement (Oracle CPU Jul 2026).

Mitigation and workarounds

Oracle strongly recommends applying the July 2026 Critical Patch Update patches as soon as possible. The patched versions for Oracle Java SE are those released after 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; similarly, GraalVM for JDK and GraalVM Enterprise Edition users should apply the corresponding CPU patches. As a temporary measure, blocking network protocols required by the attack or restricting access to sandboxed Java Web Start and applet environments may reduce risk, though Oracle notes these are not long-term solutions. Organizations not using sandboxed Java Web Start applications or applets are not affected by this vulnerability (Oracle CPU Jul 2026).

Community reactions

The vulnerability was detected by Qualys scanners and noted in Tenable's plugin pipeline shortly after disclosure, indicating routine uptake by vulnerability management vendors. No notable researcher commentary, media coverage, or significant community discussion has been identified beyond standard CPU tracking, consistent with the low severity rating of this vulnerability.

Additional resources


SourceThis report was generated using AI

Related OpenJDK JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47063HIGH7.5
  • OpenJDK JDK logoOpenJDK JDK
  • java-21-openjdk-static-libs-slowdebug
NoYesJul 21, 2026
CVE-2026-47057HIGH7.5
  • OpenJDK JDK logoOpenJDK JDK
  • openjdk-11
NoYesJul 21, 2026
CVE-2026-47058HIGH7.4
  • OpenJDK JDK logoOpenJDK JDK
  • java-1.8.0-openjdk-devel-slowdebug
NoYesJul 21, 2026
CVE-2026-60147MEDIUM6.5
  • OpenJDK JDK logoOpenJDK JDK
  • java-21-openjdk-devel
NoYesJul 21, 2026
CVE-2026-47059LOW3.7
  • OpenJDK JDK logoOpenJDK JDK
  • java-1.8.0-openjdk-demo-slowdebug
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management