CVE-2026-47057: Integer Overflow
Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE.
Other sources
There is an integer overflow in TypedArray.prototype.set() which can cause a DoS.
— Red Hat
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47057?
CVE-2026-47057 has a severity rating of high, with a score of 7.5.
How do I fix CVE-2026-47057?
To fix CVE-2026-47057, update to a patched version of Oracle Java SE that is not affected by this vulnerability.
What type of vulnerability is CVE-2026-47057?
CVE-2026-47057 is an integer overflow vulnerability in the TypedArray.prototype.set() function.
What impact does CVE-2026-47057 have?
CVE-2026-47057 can lead to a denial of service (DoS) by exploiting the integer overflow.
Which versions of Oracle Java SE are affected by CVE-2026-47057?
Oracle Java SE versions 8u491, 8u491-perf, and 11.0.31 are affected by CVE-2026-47057.