Skip to content
USN-8331-1: OpenJDK 11 vulnerabilities

USN-8331-1: OpenJDK 11 vulnerabilities

Ubuntu May 28, 2026

Thomas Beckers discovered that the JAXP component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. ( CVE-2026-22016 ) It was discovered that the Networking component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-34282 ) It was discovered that the JSSE component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-22021 ) It was discovered that the JGSS component of OpenJDK 11 did not correctly authenticate certain APIs. A remote attacker could possibly use this...

Thomas Beckers discovered that the JAXP component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. ( CVE-2026-22016 )

It was discovered that the Networking component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-34282 )

It was discovered that the JSSE component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-22021 )

It was discovered that the JGSS component of OpenJDK 11 did not correctly authenticate certain APIs. A remote attacker could possibly use this...

Thomas Beckers discovered that the JAXP component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. ( CVE-2026-22016 ) It was discovered that the Networking component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-34282 ) It was discovered that the JSSE component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-22021 ) It was discovered that the JGSS component of OpenJDK 11 did not correctly authenticate certain APIs. A remote attacker could possibly use this issue to obtain sensitive information. ( CVE-2026-22013 ) It was discovered that the 2D component of OpenJDK 11 did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to leak sensitive information. ( CVE-2026-23865 ) It was discovered that the Libraries component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-22018 ) Ken Pyle discovered that the Security component of OpenJDK 11 did not correctly authenticate certain APIs. A local attacker could possibly use this issue to leak sensitive information. ( CVE-2026-22007 , CVE-2026-34268 ) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information:

Thomas Beckers discovered that the JAXP component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. ( CVE-2026-22016 )

It was discovered that the Networking component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-34282 )

It was discovered that the JSSE component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-22021 )

It was discovered that the JGSS component of OpenJDK 11 did not correctly authenticate certain APIs. A remote attacker could possibly use this issue to obtain sensitive information. ( CVE-2026-22013 )

It was discovered that the 2D component of OpenJDK 11 did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to leak sensitive information. ( CVE-2026-23865 )

It was discovered that the Libraries component of OpenJDK 11 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. ( CVE-2026-22018 )

Ken Pyle discovered that the Security component of OpenJDK 11 did not correctly authenticate certain APIs. A local attacker could possibly use this issue to leak sensitive information. ( CVE-2026-22007 , CVE-2026-34268 )

In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.

Please see the following for more information:

This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any running Java applications to make all the necessary changes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.