CVE-2026-6918 Details
Description
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
A denial-of-service vulnerability has been identified in Eclipse OpenJ9 JITServer versions 0.21 prior to 0.59. A remote attacker can crash the server by sending a 32-byte crafted TCP message. The vulnerability arises because the message deserialization process does not properly validate the size of data being read, allowing for an out-of-bounds heap read that leads to a segmentation fault. This issue affects JITServer deployments running without TLS client authentication, which is the default configuration.
Users can upgrade to Eclipse OpenJ9 version 0.59 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:22328 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-6918 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2466741 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6918.json | redhat-SADP | |
| https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-q393-vr4c-969r | CISA-ADP | ExploitVendor Advisory |
| https://github.com/eclipse-openj9/openj9/pull/23793 | [email protected] | Issue TrackingPatch |
| https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-q393-vr4c-969r | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| eclipse openj9 | >= 0.21.0, < 0.59.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | Initial Analysis | [email protected] |
| May 5, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | New CVE Received | [email protected] |