java-17-openjdk

Direct Vulnerabilities

Known vulnerabilities in the java-17-openjdk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Out-of-bounds Write

<1:17.0.20.0.8-1.1.el8
  • H
Improper Certificate Validation

<1:17.0.20.0.8-1.1.el8
  • H
Improper Verification of Cryptographic Signature

<1:17.0.20.0.8-1.1.el8
  • H
Resource Exhaustion

<1:17.0.20.0.8-1.1.el8
  • H
NULL Pointer Dereference

<1:17.0.20.0.8-1.1.el8
  • H
Improper Certificate Validation

<1:17.0.20.0.8-1.1.el8
  • H
Inefficient Regular Expression Complexity

<1:17.0.20.0.8-1.1.el8
  • H
Resource Exhaustion

<1:17.0.20.0.8-1.1.el8
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.19.0.10-1.el8
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:17.0.19.0.10-1.el8
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:17.0.19.0.10-1.el8
  • H
Cleartext Transmission of Sensitive Information

<1:17.0.19.0.10-1.el8
  • H
Uncontrolled Recursion

<1:17.0.19.0.10-1.el8
  • H
Out-of-bounds Write

*
  • H
Out-of-bounds Read

<1:17.0.19.0.10-1.el8
  • H
XML External Entity (XXE) Injection

<1:17.0.19.0.10-1.el8
  • H
Integer Overflow or Wraparound

<1:17.0.20.0.8-1.1.el8
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

<1:17.0.19.0.10-1.el8
  • H
Buffer Underflow

<1:17.0.19.0.10-1.el8
  • H
Out-of-bounds Write

<1:17.0.19.0.10-1.el8
  • H
CVE-2026-23865

<1:17.0.19.0.10-1.el8
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Buffer Overflow

*
  • H
Improper Certificate Validation

<1:17.0.18.0.8-1.el8
  • H
Key Exchange without Entity Authentication

<1:17.0.18.0.8-1.el8
  • H
CRLF Injection

<1:17.0.18.0.8-1.el8
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Read

<1:17.0.19.0.10-1.el8
  • H
Out-of-bounds Read

<1:17.0.19.0.10-1.el8
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Read

<1:17.0.18.0.8-1.el8
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

<1:17.0.18.0.8-1.el8
  • M
CVE-2025-53066

<1:17.0.17.0.10-1.el8
  • M
Inappropriate Encoding for Output Context

<1:17.0.17.0.10-1.el8
  • H
Heap-based Buffer Overflow

<1:17.0.16.0.8-2.el8
  • H
Information Exposure

<1:17.0.16.0.8-2.el8
  • H
Missing Required Cryptographic Step

<1:17.0.16.0.8-2.el8
  • H
Heap-based Buffer Overflow

<1:17.0.16.0.8-2.el8
  • M
Buffer Overflow

<1:17.0.15.0.6-2.el8
  • M
Information Exposure

<1:17.0.15.0.6-2.el8
  • M
Heap-based Buffer Overflow

<1:17.0.15.0.6-2.el8
  • M
Signed to Unsigned Conversion Error

<1:17.0.14.0.7-3.el8
  • M
Signed to Unsigned Conversion Error

<1:17.0.13.0.11-3.el8
  • M
Uncontrolled Memory Allocation

<1:17.0.13.0.11-3.el8
  • M
Integer Overflow or Wraparound

<1:17.0.13.0.11-3.el8
  • M
Improper Handling of Length Parameter Inconsistency

<1:17.0.13.0.11-3.el8
  • H
Out-of-bounds Write

<1:17.0.12.0.7-2.el8
  • H
CVE-2024-21140

<1:17.0.12.0.7-2.el8
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.12.0.7-2.el8
  • H
CVE-2024-21147

<1:17.0.12.0.7-2.el8
  • H
CVE-2024-21131

<1:17.0.12.0.7-2.el8
  • M
Out-of-bounds Write

<1:17.0.11.0.9-2.el8
  • M
Integer Overflow or Wraparound

<1:17.0.11.0.9-2.el8
  • M
Reliance on Reverse DNS Resolution for a Security-Critical Action

<1:17.0.11.0.9-2.el8
  • M
Improper Output Neutralization for Logs

<1:17.0.11.0.9-2.el8
  • H
Improper Input Validation

<1:17.0.10.0.7-2.el8
  • H
Covert Timing Channel

<1:17.0.10.0.7-2.el8
  • H
Out-of-bounds Write

<1:17.0.10.0.7-2.el8
  • H
Improper Input Validation

<1:17.0.10.0.7-2.el8
  • H
Information Exposure Through Log Files

<1:17.0.10.0.7-2.el8
  • H
Improper Input Validation

<1:17.0.10.0.7-2.el8
  • M
Out-of-Bounds

<1:17.0.13.0.11-3.el8
  • M
Improper Certificate Validation

<1:17.0.9.0.9-2.el8
  • M
Out-of-Bounds

<1:17.0.9.0.9-2.el8
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.8.0.7-2.el8
  • M
Small Space of Random Values

<1:17.0.8.0.7-2.el8
  • M
Out-of-bounds Read

<1:17.0.8.0.7-2.el8
  • M
Out-of-bounds Read

<1:17.0.8.0.7-2.el8
  • M
Directory Traversal

<1:17.0.8.0.7-2.el8
  • M
Directory Traversal

<1:17.0.8.0.7-2.el8
  • H
Improper Input Validation

<1:17.0.7.0.7-1.el8_7
  • H
Improperly Implemented Security Check for Standard

<1:17.0.7.0.7-1.el8_7
  • H
Improper Input Validation

<1:17.0.7.0.7-1.el8_7
  • H
Improper Neutralization of Null Byte or NUL Character

<1:17.0.7.0.7-1.el8_7
  • H
Information Exposure

<1:17.0.7.0.7-1.el8_7
  • H
Improper Neutralization of Null Byte or NUL Character

<1:17.0.7.0.7-1.el8_7
  • H
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1:17.0.7.0.7-1.el8_7
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.8.0.7-2.el8
  • M
Resource Exhaustion

<1:17.0.6.0.10-3.el8_7
  • M
Reliance on File Name or Extension of Externally-Supplied File

<1:17.0.6.0.10-3.el8_7
  • M
Authentication Bypass

<1:17.0.5.0.8-2.el8_6
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.5.0.8-2.el8_6
  • M
Resource Exhaustion

<1:17.0.5.0.8-2.el8_6
  • M
Use of Insufficiently Random Values

<1:17.0.5.0.8-2.el8_6
  • M
Integer Coercion Error

<1:17.0.5.0.8-2.el8_6
  • M
Buffer Overflow

<1:17.0.5.0.8-2.el8_6
  • H
Integer Coercion Error

<1:17.0.4.0.8-2.el8_6
  • H
Inconsistency Between Implementation and Documented Design

<1:17.0.4.0.8-2.el8_6
  • H
Improper Access Control

<1:17.0.4.0.8-2.el8_6
  • H
Resource Leak

<1:17.0.4.0.8-2.el8_6
  • M
Integer Overflow or Wraparound

<1:17.0.5.0.8-2.el8_6
  • H
Improper Verification of Cryptographic Signature

<1:17.0.3.0.6-2.el8_5
  • H
Improper Use of Validation Framework

<1:17.0.3.0.6-2.el8_5
  • H
Incorrect Behavior Order: Early Validation

<1:17.0.3.0.6-2.el8_5
  • H
Integer Underflow

<1:17.0.3.0.6-2.el8_5
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<1:17.0.3.0.6-2.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:17.0.3.0.6-2.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.2.0.8-4.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.2.0.8-4.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.2.0.8-4.el8_5
  • M
Deserialization of Untrusted Data

<1:17.0.2.0.8-4.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.2.0.8-4.el8_5
  • M
Integer Overflow or Wraparound

<1:17.0.2.0.8-4.el8_5
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.2.0.8-4.el8_5
  • M
XML External Entity (XXE) Injection

<1:17.0.2.0.8-4.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.2.0.8-4.el8_5
  • M
Deserialization of Untrusted Data

<1:17.0.2.0.8-4.el8_5
  • M
Out-of-bounds Write

<1:17.0.2.0.8-4.el8_5
  • M
Uncaught Exception

<1:17.0.2.0.8-4.el8_5
  • M
Improper Cross-boundary Removal of Sensitive Data

<1:17.0.2.0.8-4.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.2.0.8-4.el8_5
  • M
Deserialization of Untrusted Data

<1:17.0.2.0.8-4.el8_5
  • H
Information Exposure

<1:17.0.1.0.12-2.el8_5
  • H
NULL Pointer Dereference

<1:17.0.1.0.12-2.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:17.0.1.0.12-2.el8_5
  • H
Incorrect Authorization

<1:17.0.1.0.12-2.el8_5
  • H
Improper Input Validation

<1:17.0.1.0.12-2.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:17.0.1.0.12-2.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:17.0.1.0.12-2.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:17.0.1.0.12-2.el8_5