Improper input validation in Oracle Java SE - CVE-2026-22008

 

Improper input validation in Oracle Java SE - CVE-2026-22008

Published: April 22, 2026


Vulnerability identifier: #VU126763
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22008
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper input validation within the Libraries component in Oracle Java SE. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.


Affected software

Oracle Java SE
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Basesystem Module
Ubuntu
IBM Sterling Connect:Direct FTP+
IBM MQ Operator
IBM Power Hardware Management Console (HMC)
EMC Data Protection Advisor
IBM Decision Optimization for Cloud Pak for Data
IBM Sterling Connect:Direct for UNIX
SPSS Statistics
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM supplied MQ Advanced container images
DB2 Query Management Facility
Data Product Hub
IBM Sterling Connect:Direct for Microsoft Windows
IBM MQ Appliance
media-libs/freetype
java-25-openjdk (Red Hat package)
java-25-openjdk-headless-debuginfo
java-25-openjdk
java-25-openjdk-debuginfo
java-25-openjdk-devel-debuginfo
java-25-openjdk-demo
java-25-openjdk-devel
java-25-openjdk-headless
openjdk-25-crac (Ubuntu package)
openjdk-25 (Debian package)
openjdk-25 (Ubuntu package)
openjdk-26 (Ubuntu package)

How to mitigate CVE-2026-22008

Install updates from vendor's website.

IBM Sterling Connect:Direct FTP+ - update to 1.3.0.5
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1064.1, 11.1.1112.1
EMC Data Protection Advisor - addressed in versions 19.12 SP1, 19.12 SP2
media-libs/freetype - update to 2.14.3
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
Data Product Hub - addressed in versions 5.3.1 Patch 7, 5.4.0
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.62, 6.4.0.4.35
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.7.iFix015, 6.4.0.5.iFix020
IBM MQ Appliance - addressed in versions 9.4.0.25, 9.4.5.2
java-25-openjdk (Red Hat package) - addressed in versions 25.0.3.0.9-1.el9, 25.0.3.0.9-1.el10_2
java-25-openjdk-headless-debuginfo - update to 25.0.3.0-150700.15.10.1
java-25-openjdk - update to 25.0.3.0-150700.15.10.1
java-25-openjdk-debuginfo - update to 25.0.3.0-150700.15.10.1
java-25-openjdk-devel-debuginfo - update to 25.0.3.0-150700.15.10.1
java-25-openjdk-demo - update to 25.0.3.0-150700.15.10.1
java-25-openjdk-devel - update to 25.0.3.0-150700.15.10.1
java-25-openjdk-headless - update to 25.0.3.0-150700.15.10.1
openjdk-25-crac (Ubuntu package) - addressed in versions 25.0.3+9-0ubuntu1~25.10.1, 25.0.3+9-0ubuntu1~26.04.1
openjdk-25 (Debian package) - update to 25.0.3+9-2~deb13u1
openjdk-25 (Ubuntu package) - addressed in versions 25.0.3+9-2~22.04.2, 25.0.3+9-2~24.04.2, 25.0.3+9-2~25.10.2, 25.0.3+9-2~26.04.2
openjdk-26 (Ubuntu package) - addressed in versions 26.0.1+8-2~25.10.2, 26.0.1+8-2~26.04.2
SPSS Statistics - addressed in versions 27.0.1.0 IF036, 28.0.1.1 IF018, 29.0.2.0 IF019, 30.0.0.0 IF015, 31.0.2.0 IF007

External References

Related Security Bulletins