OpenJDK 21 and 25 Vulnerabilities Expose Sensitive Data Risks

OpenJDK 21 and 25 Vulnerabilities Expose Sensitive Data Risks

First seen 25 Nov 2025, 12:28 UTC UbuntuLinuxsecurity 88% similarity 17.9

Article Content

Browse articles
ThreatCluster

OpenJDK versions 21 and 25 have been found to contain vulnerabilities that allow unauthenticated remote attackers to potentially modify files or leak sensitive information. The issues were discovered in the Security component and the JAXP component, with specific vulnerabilities identified as CVE-2025-53057. Both versions are affected by improper handling of encoded strings and XML External Entity (XEE) attacks.

ThreatCluster AI

Community

Browse all →