Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial‑of‑Service Vulnerability in Oracle Java SE 2D Component | OpenJDK: Improve font loading (2026-08 Security Update) |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openjdk |
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openjdk:25 cpe:/o:redhat:enterprise_linux:10.2 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openjdk |
|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 19 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial‑of‑Service Vulnerability in Oracle Java SE 2D Component | |
| Weaknesses | CWE-749 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). | |
| First Time appeared |
Oracle
Oracle java Se |
|
| CPEs | cpe:2.3:a:oracle:java_se:25.0.4:*:*:*:*:*:*:* cpe:2.3:a:oracle:java_se:26.0.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle java Se |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-08-18T21:02:27.077Z
Reserved: 2026-08-04T22:06:34.605Z
Link: CVE-2026-70906
No data.
Status : Awaiting Analysis
Published: 2026-08-18T21:17:48.393
Modified: 2026-08-20T13:07:28.683
Link: CVE-2026-70906
OpenCVE Enrichment
Updated: 2026-08-19T09:30:03Z
Weaknesses