Skip to main content
EPSS 0.1%top 98%

Red Hat Security Advisory: OpenJDK 17.0.19 Security Update for Windows Builds

0
High
Published: 04/23/2026 (04/23/2026, 16:08:36 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The OpenJDK 17 packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. This release of the Red Hat build of OpenJDK 17 (17.0.19) for Windows serves as a replacement for the Red Hat build of OpenJDK 17 (17.0.18) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * JDK: Enhance crypto algorithm support (CVE-2026-22007) * JDK: Improve Kerberos credentialing (CVE-2026-22013) * JDK: Enhance Path Factories Redux (CVE-2026-22016) * JDK: Enhance Zip file reading (CVE-2026-22018) * JDK: Enhance certificate chain validation (CVE-2026-22021) * JDK: Updating FreeType 2.14.1 (CVE-2026-23865) * JDK: Enhance TLS connection handling (CVE-2026-34282) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64java-21-openjdk-main@aarch64Red Hat OpenJDKOPENJDK ELS 11.0.31OpenJDKRed Hat Build of OpenJDK 17.0.19

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/02/2026, 22:04:01 UTC

Technical Analysis

This advisory from Red Hat Product Security covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, specifically targeting java-21-openjdk packages across multiple variants and architectures (aarch64, x86_64). The update addresses multiple CVEs (eight in total, including CVE-2026-22007) related to various weaknesses such as CWE-327, CWE-319, CWE-611, CWE-125, CWE-674, and CWE-835. The advisory does not provide detailed technical descriptions of the vulnerabilities or explicit patch versions but confirms the availability of updated RPMs. No exploits are currently known in the wild.

Potential Impact

The vulnerabilities addressed by this update affect Red Hat Hardened Images and java-21-openjdk packages, potentially impacting the security and stability of systems using these components. The exact impact of each CVE is not detailed in the advisory. The severity is classified as high, indicating significant security concerns if left unpatched. No active exploitation has been reported.

Mitigation Recommendations

A security update containing bug fixes and enhancements for the affected java-21-openjdk RPMs is available from Red Hat. Users should apply the update as provided by Red Hat Hardened Images to remediate the vulnerabilities. Since this is an official Red Hat advisory with updated packages released, applying the update is the recommended mitigation. Patch status is confirmed by the vendor advisory. No additional or alternative mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:9256
Cve Count
8
Additional Cves
["CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"]
State
PUBLISHED

Threat ID: 6a16097ce29bf47b50648b19

Added to database: 05/26/2026, 20:58:36 UTC

Last enriched: 08/02/2026, 22:04:01 UTC

Last updated: 09/14/2026, 22:01:32 UTC

Views: 121

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses