CVE-2026-16439: Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
Published Jul 21, 2026
·Updated
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
Affected Software
5 affected components
Eclipse Openj9<=0.60
IBM WebSphere Application Server<=8.5
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server - Liberty<=Continuous delivery
Eclipse Openj9>=0.8.0<0.60.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse OpenJ9to a version that resolves this vulnerability.Fixed in 0.60
Event History
Jul 21, 2026
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
DescriptionWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 4, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-16439?
The severity of CVE-2026-16439 is classified as medium with a CVSS score of 5.8.
2
How do I fix CVE-2026-16439?
To fix CVE-2026-16439, upgrade to a patched version of Eclipse OpenJ9 released after 0.60.
3
What vulnerability does CVE-2026-16439 describe?
CVE-2026-16439 describes a buffer underflow issue when using the -Xtrace option in Eclipse OpenJ9.
4
Which versions of Eclipse OpenJ9 are affected by CVE-2026-16439?
Eclipse OpenJ9 versions up to 0.60 are affected by CVE-2026-16439.
5
What impact does CVE-2026-16439 have on Eclipse OpenJ9?
CVE-2026-16439 can potentially lead to buffer underflow when tracing method arguments, which may affect application stability and security.