java-21-openjdk

Direct Vulnerabilities

Known vulnerabilities in the java-21-openjdk package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Validation of Consistency within Input

*
  • M
Improper Validation of Consistency within Input

*
  • M
Improper Validation of Consistency within Input

*
  • M
Improper Validation of Consistency within Input

*
  • M
Improper Validation of Consistency within Input

*
  • M
CVE-2026-70907

<0:21.0.12.1.1-1.0.hum1
  • M
CVE-2026-70907

<1:21.0.12.1.1-1.2.el10
  • M
CVE-2026-70907

<1:21.0.12.1.1-1.1.el10
  • M
CVE-2026-60589

<0:21.0.12.1.1-1.0.hum1
  • M
CVE-2026-60589

<1:21.0.12.1.1-1.2.el10
  • M
CVE-2026-60589

<1:21.0.12.1.1-1.1.el10
  • M
CVE-2026-61308

<0:21.0.12.1.1-1.0.hum1
  • M
CVE-2026-61308

<1:21.0.12.1.1-1.2.el10
  • M
CVE-2026-61308

<1:21.0.12.1.1-1.1.el10
  • M
Improper Certificate Validation

<1:21.0.12.0.8-1.2.el10_2
  • M
Improper Certificate Validation

<1:21.0.12.0.8-1.1.el10_2
  • M
Inefficient Regular Expression Complexity

<1:21.0.12.0.8-1.2.el10_2
  • M
Inefficient Regular Expression Complexity

<1:21.0.12.0.8-1.1.el10_2
  • L
Out-of-bounds Write

<1:21.0.12.0.8-1.2.el10_2
  • L
Out-of-bounds Write

<1:21.0.12.0.8-1.1.el10_2
  • L
NULL Pointer Dereference

<1:21.0.12.0.8-1.2.el10_2
  • L
NULL Pointer Dereference

<1:21.0.12.0.8-1.1.el10_2
  • M
Resource Exhaustion

<1:21.0.12.0.8-1.2.el10_2
  • M
Resource Exhaustion

<1:21.0.12.0.8-1.1.el10_2
  • M
Improper Certificate Validation

<1:21.0.12.0.8-1.2.el10_2
  • M
Improper Certificate Validation

<1:21.0.12.0.8-1.1.el10_2
  • M
Integer Overflow or Wraparound

<1:21.0.12.0.8-1.2.el10_2
  • M
Integer Overflow or Wraparound

<1:21.0.12.0.8-1.1.el10_2
  • H
Improper Verification of Cryptographic Signature

<1:21.0.12.0.8-1.2.el10_2
  • H
Improper Verification of Cryptographic Signature

<1:21.0.12.0.8-1.1.el10_2
  • M
Resource Exhaustion

<1:21.0.12.0.8-1.2.el10_2
  • M
Resource Exhaustion

<1:21.0.12.0.8-1.1.el10_2
  • M
Resource Exhaustion

<0:21.0.12.0.8-0.1.hum1
  • M
Expired Pointer Dereference

<1:21.0.11.0.10-2.el10_2
  • M
Expired Pointer Dereference

<1:21.0.11.0.10-1.el10_2
  • L
NULL Pointer Dereference

<0:21.0.12.0.8-0.1.hum1
  • H
Out-of-bounds Write

<1:21.0.11.0.10-2.el10_2
  • H
Out-of-bounds Write

<1:21.0.11.0.10-1.el10_2
  • M
Improper Certificate Validation

<0:21.0.12.0.8-0.1.hum1
  • M
Buffer Underflow

<1:21.0.11.0.10-2.el10_2
  • M
Buffer Underflow

<1:21.0.11.0.10-1.el10_2
  • M
Out-of-bounds Read

<1:21.0.11.0.10-2.el10_2
  • M
Out-of-bounds Read

<1:21.0.11.0.10-1.el10_2
  • L
Out-of-bounds Write

<0:21.0.12.0.8-0.1.hum1
  • M
Improper Certificate Validation

<0:21.0.12.0.8-0.1.hum1
  • M
Inefficient Regular Expression Complexity

<0:21.0.12.0.8-0.1.hum1
  • H
Improper Verification of Cryptographic Signature

<0:21.0.12.0.8-0.1.hum1
  • M
Resource Exhaustion

<0:21.0.12.0.8-0.1.hum1
  • M
Out-of-bounds Read

<1:21.0.11.0.10-2.el10_2
  • M
Out-of-bounds Read

<1:21.0.11.0.10-1.el10_2
  • M
CVE-2026-23865

<1:21.0.11.0.10-2.el10_2
  • M
CVE-2026-23865

<1:21.0.11.0.10-1.el10_2
  • L
Use of a Broken or Risky Cryptographic Algorithm

<1:21.0.11.0.10-2.el10_2
  • L
Use of a Broken or Risky Cryptographic Algorithm

<1:21.0.11.0.10-1.el10_2
  • M
Cleartext Transmission of Sensitive Information

<1:21.0.11.0.10-2.el10_2
  • M
Cleartext Transmission of Sensitive Information

<1:21.0.11.0.10-1.el10_2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:21.0.11.0.10-2.el10_2
  • M
Uncontrolled Recursion

<1:21.0.11.0.10-2.el10_2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:21.0.11.0.10-1.el10_2
  • M
Uncontrolled Recursion

<1:21.0.11.0.10-1.el10_2
  • H
XML External Entity (XXE) Injection

<1:21.0.11.0.10-2.el10_2
  • H
XML External Entity (XXE) Injection

<1:21.0.11.0.10-1.el10_2
  • L
Out-of-bounds Read

<1:21.0.11.0.10-2.el10_2
  • L
Out-of-bounds Read

<1:21.0.11.0.10-1.el10_2
  • L
Use of a Broken or Risky Cryptographic Algorithm

<1:21.0.11.0.10-2.el10_2
  • L
Use of a Broken or Risky Cryptographic Algorithm

<1:21.0.11.0.10-1.el10_2
  • L
Out-of-bounds Read

<0:21.0.11.0.10-1.hum1
  • L
Use of a Broken or Risky Cryptographic Algorithm

<0:21.0.11.0.10-1.hum1
  • L
Use of a Broken or Risky Cryptographic Algorithm

<0:21.0.11.0.10-1.hum1
  • M
Cleartext Transmission of Sensitive Information

<0:21.0.11.0.10-1.hum1
  • H
XML External Entity (XXE) Injection

<0:21.0.11.0.10-1.hum1
  • M
Uncontrolled Recursion

<0:21.0.11.0.10-1.hum1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:21.0.11.0.10-1.hum1
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Underflow

*
  • M
Buffer Underflow

*
  • M
Buffer Underflow

*
  • M
Buffer Underflow

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Buffer Overflow

*
  • H
Out-of-bounds Read

<1:21.0.10.0.7-1.el10
  • H
Out-of-bounds Read

<1:21.0.10.0.7-1.el10
  • M
Key Exchange without Entity Authentication

<1:21.0.10.0.7-1.el10
  • M
Key Exchange without Entity Authentication

<1:21.0.10.0.7-1.el10
  • H
Improper Certificate Validation

<1:21.0.10.0.7-1.el10
  • H
Improper Certificate Validation

<1:21.0.10.0.7-1.el10
  • H
Out-of-bounds Write

<1:21.0.10.0.7-1.el10
  • H
Out-of-bounds Write

<1:21.0.10.0.7-1.el10
  • M
CRLF Injection

<1:21.0.10.0.7-1.el10
  • M
CRLF Injection

<1:21.0.10.0.7-1.el10
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Object Model Violation: Just One of Equals and Hashcode Defined

<1:21.0.9.0.10-1.el10
  • M
CVE-2025-53066

<1:21.0.9.0.10-1.el10
  • M
Inappropriate Encoding for Output Context

<1:21.0.9.0.10-1.el10
  • M
Missing Required Cryptographic Step

<1:21.0.8.0.9-1.el10
  • H
Heap-based Buffer Overflow

<1:21.0.8.0.9-1.el10
  • H
Information Exposure

<1:21.0.8.0.9-1.el10
  • H
Heap-based Buffer Overflow

<1:21.0.8.0.9-1.el10
  • M
CVE-2024-21140

*
  • M
Information Exposure

<1:21.0.7.0.6-1.el10
  • M
Heap-based Buffer Overflow

<1:21.0.7.0.6-1.el10
  • M
Buffer Overflow

<1:21.0.7.0.6-1.el10