Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: OpenJDK 11.0.31 ELS Security Update for Windows Builds

0
High
Published: Wed Apr 22 2026 (04/22/2026, 15:44:44 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has released an important security update for its OpenJDK 11 Extended Lifecycle Support (ELS) Windows builds, version 11. 0. 31, replacing version 11. 0. 30. This update addresses eight security vulnerabilities in the OpenJDK 11 Java Runtime Environment and Software Development Kit, identified by CVE identifiers CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, and CVE-2026-34282. The update also includes bug fixes and enhancements. Red Hat rates the security impact of this update as Important. No known exploits in the wild have been reported. Users of affected OpenJDK 11 ELS versions on Windows should apply this update following Red Hat's guidance.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 22:22:57 UTC

Technical Analysis

This Red Hat security advisory covers the OpenJDK 11.0.31 ELS update for Windows builds, which replaces version 11.0.30. The update addresses eight distinct security vulnerabilities in the OpenJDK 11 Java Runtime Environment and Software Development Kit. The vulnerabilities correspond to CVEs CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, and CVE-2026-34282. The advisory does not provide CVSS scores but classifies the impact as Important. The update also includes bug fixes and enhancements. The affected products include Red Hat OpenJDK 11 ELS for various RHEL versions and architectures. No known exploits in the wild have been reported. The vendor advisory recommends applying this update after ensuring all prior relevant errata are applied.

Potential Impact

The update addresses multiple security vulnerabilities in the OpenJDK 11 runtime and SDK, which could potentially impact the security posture of systems running affected versions. The vulnerabilities span several CWE categories including cryptographic issues (CWE-327), information exposure (CWE-319), XML external entity issues (CWE-611), buffer overflows (CWE-125), resource management errors (CWE-674), and out-of-bounds reads (CWE-835). Red Hat rates the overall security impact as Important (high severity). There are no reports of known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released an updated OpenJDK 11 ELS version 11.0.31 that includes fixes for the identified vulnerabilities. Users should apply this update promptly to mitigate the security risks. Before applying the update, ensure all previously released relevant errata are installed. Detailed update instructions are available in the Red Hat advisory and documentation. Since this is a product update, no additional mitigation steps beyond applying the official update are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:9256
Cve Count
8
Additional Cves
["CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"]
Cvss Version
null

Threat ID: 6a16097ce29bf47b50648b19

Added to database: 5/26/2026, 8:58:36 PM

Last enriched: 5/26/2026, 10:22:57 PM

Last updated: 5/27/2026, 4:51:29 AM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses