RHSA-2026:55783: Moderate: OpenJDK 17.0.20.1 Security Update for Windows Builds
Moderate: OpenJDK 17.0.20.1 Security Update for Windows Builds
Other sources
The OpenJDK 17 packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.This release of the Red Hat build of OpenJDK 17 (17.0.20.1) for Windows serves as a replacement for the Red Hat build of OpenJDK 17 (17.0.20) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): JDK: Improve Resource Resolving (CVE-2026-60589) JDK: Enhance HTTP Connections (CVE-2026-61308) JDK: Enhance TLS server (CVE-2026-70907) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenJDK 17 (Red Hat build) for Windowsto a version that resolves this vulnerability.Fixed in 17.0.20.1 - Compensating control
Before applying the OpenJDK 17.0.20.1 update, ensure all previously released errata relevant to your system have been applied.
Event History
Frequently Asked Questions
Which environments should be reviewed for this update?
Review Windows deployments of Red Hat OpenJDK Java for Middleware. The advisory is specifically identified as a security update for Windows builds.
How should this update be prioritized?
The advisory is rated medium severity (4) with a risk value of 19. Prioritize it according to the organization’s handling requirements for medium-severity Java runtime security updates.