﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
23218	jdk-21.0.12.1	Douglas R. Reno	SecurityAdvisory	"New quarterly OpenJDK release.

This includes fixes for the following security vulnerabilities:

- CVE-2026-22016 in the JAXP component. Rated as 7.5 High, low attack complexity and no privileges required. It is remotely exploitable and allows for trivial remote access to any information that the Java process is able to access.

- CVE-2026-34282 in the Networking component. Rated as 7.5 High, low attack complexity and no privileges required. It is remotely exploitable and allows for easy crashes of Java applications.

- CVE-2026-22021 in the JSSE component. Rated as 5.3 Medium. Remotely exploitable with low attack complexity and no privileges required. It allows for easy crashes of Java applications.

- CVE-2026-22013 in the JGSS component. Rated as 5.3 Medium. Remotely exploitable with no privileges required, but the vulnerability is complex to exploit. Successful exploitation though allows for remote access to any information that the Java process is able to access.

- CVE-2026-23865 in the 2D (Freetype) component. Rated as 5.3 Medium. Only exploitable locally and allows for a malicious font in a Java program to cause denial of service, and a low chance of information disclosure or arbitrary code execution.

- CVE-2026-22018 in the Libraries component. Rated as 3.7 Low. Remotely exploitable vulnerability with High attack complexity and no privileges required. It allows for a remote attacker to crash a Java program.

- CVE-2026-22007 in the Security component. Rated as 2.9 Low. Local attackers can possibly access all information on a system that a Java process can access without any privileges required or user interaction.

- CVE-2026-34628 in the Security component. Rated as 2.9 Low. Local attackers can possibly access all information on a system that a Java process can access without any privileges required or user interaction.

Note that of the above vulnerabilities, only the FreeType and the JGSS issues require any user interaction to successfully exploit."	enhancement	closed	high	98-Security	BOOK	git	medium	fixed		
