Skip to content
OracleCVE-2026-71054

Oracle Java SE: resource exhaustion

Medium6.5CVE-2026-71054 · Published Aug 26, 2026 · updated Aug 28, 2026

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).

Oracle advisory

Affected versions

PackageAffectedFixed in
Oracle Java SE
Product
<= 7u511No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770

More Oracle advisories

All Oracle
Advisory
Helidon: data tampering via Imperative Web Server
High8.6Aug 18
Helidon: data tampering via Imperative Web Server
Critical9.9Aug 18
Helidon: data tampering via Imperative Web Server
High8.3Aug 18
Helidon: flaw in Imperative Web Server
Medium5.3Aug 18
Helidon: data tampering via Imperative Web Server
High7.3Aug 18
Helidon: denial of service via Imperative Web Server
High7.5Aug 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.