CVE-2026-46917
Publication date 21 July 2026
Last updated 26 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openjdk-8 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| openjdk-9 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 16.04 LTS xenial | Ignored no longer supported by upstream | |
| openjdk-lts | 26.04 LTS resolute |
Fixed 11.0.32+9-1ubuntu1~26.04
|
| 24.04 LTS noble |
Fixed 11.0.32+9-1ubuntu1~24.04
|
|
| 22.04 LTS jammy |
Fixed 11.0.32+9-1ubuntu1~22.04
|
|
| 20.04 LTS focal |
Fixed 11.0.32+9-1ubuntu1~20.04
|
|
| 18.04 LTS bionic |
Fixed 11.0.32+9-1ubuntu1~18.04
|
|
| openjdk-13 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Ignored superseded by openjdk-17 | |
| openjdk-16 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Ignored superseded by openjdk-17 | |
| openjdk-17 | 26.04 LTS resolute |
Fixed 17.0.20+8-1~26.04
|
| 24.04 LTS noble |
Fixed 17.0.20+8-1~24.04
|
|
| 22.04 LTS jammy |
Fixed 17.0.20+8-1~22.04
|
|
| 20.04 LTS focal |
Fixed 17.0.20+8-1~20.04
|
|
| 18.04 LTS bionic |
Fixed 17.0.20+8-1~18.04
|
|
| openjdk-17-crac | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| openjdk-18 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Ignored superseded by openjdk-19 | |
| openjdk-21 | 26.04 LTS resolute |
Fixed 21.0.12+8-1~26.04
|
| 24.04 LTS noble |
Fixed 21.0.12+8-1~24.04
|
|
| 22.04 LTS jammy |
Fixed 21.0.12+8-1~22.04
|
|
| 20.04 LTS focal |
Fixed 21.0.12+8-1~20.04
|
|
| openjdk-21-crac | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| openjdk-25 | 26.04 LTS resolute |
Fixed 25.0.4+7-1~26.04
|
| 24.04 LTS noble |
Fixed 25.0.4+7-1~24.04
|
|
| 22.04 LTS jammy |
Fixed 25.0.4+7-1~22.04
|
|
| openjdk-26 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialSeverity score breakdown
CVSS version: CVSS v3.0
Base score
5.3 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
Related Ubuntu Security Notices (USN)
- USN-8681-1
- OpenJDK 25 vulnerabilities
- 26 August 2026
- USN-8677-1
- OpenJDK 21 vulnerabilities
- 25 August 2026
- USN-8676-1
- OpenJDK 17 vulnerabilities
- 25 August 2026
- USN-8674-1
- OpenJDK 11 vulnerabilities
- 25 August 2026