CVE-2026-83357: Path Traversal
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle GraalVM for JDK 17to a version that resolves this vulnerability.Fixed in 23.0.13.1 - Upgrade
Upgrade
Oracle GraalVM for JDK 21to a version that resolves this vulnerability.Fixed in 23.1.12.1 - Upgrade
Upgrade
Oracle GraalVMto a version that resolves this vulnerability.Fixed in 25.0.4.1 - Compensating control
Restrict network access to Oracle GraalVM for JDK/Oracle GraalVM via HTTP to reduce exposure to unauthenticated network attacks (AV:N).
Event History
Frequently Asked Questions
Does exploitation require credentials or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker with network access via HTTP, and it requires no user interaction.
Is exploitation expected to be straightforward?
No. The CVSS vector rates attack complexity as high, indicating exploitation is considered difficult despite being network-accessible and unauthenticated.
Which releases should be checked during triage?
Check Oracle GraalVM for JDK 17 version 23.0.13.1, Oracle GraalVM for JDK 21 version 23.1.12.1, and Oracle GraalVM version 25.0.4.1.