📦 Graalvm

by Oracle

🔍 What is Graalvm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-22931

CRITICAL CVSS 9.8 Aug 16, 2021

Node.js DNS library vulnerability allows remote code execution, XSS, and application crashes due to improper validation of DNS responses. Attackers can inject malicious hostnames leading to domain hij...

CVE-2021-29921

CRITICAL CVSS 9.8 May 6, 2021

The Python ipaddress library incorrectly interprets IP addresses with leading zeros in octets, treating them as octal numbers instead of decimal. This allows attackers to bypass IP-based access contro...

CVE-2025-53066

HIGH CVSS 7.5 Oct 21, 2025

This vulnerability in Oracle Java's JAXP component allows unauthenticated attackers to access sensitive data via network protocols. It affects multiple Java SE and GraalVM versions, particularly impac...

CVE-2025-50059

HIGH CVSS 8.6 Jul 15, 2025

This vulnerability in Oracle Java SE and GraalVM networking components allows unauthenticated attackers with network access to bypass Java sandbox security and access critical data. It primarily affec...

CVE-2025-30749

HIGH CVSS 8.1 Jul 15, 2025

This vulnerability in Oracle Java's 2D component allows an unauthenticated attacker with network access to potentially compromise Java SE, GraalVM for JDK, and GraalVM Enterprise Edition. It primarily...

CVE-2025-21587

HIGH CVSS 7.4 Apr 15, 2025

This vulnerability in Java Secure Socket Extension (JSSE) allows attackers to manipulate or access critical data in Java applications. It affects multiple Oracle Java SE and GraalVM versions and can b...

CVE-2024-20952

HIGH CVSS 7.4 Jan 16, 2024

This Java security vulnerability allows attackers to bypass sandbox protections in client-side Java deployments. It affects Java SE, GraalVM for JDK, and GraalVM Enterprise Edition when running untrus...

CVE-2024-20932

HIGH CVSS 7.5 Jan 16, 2024

This vulnerability in Oracle Java SE and GraalVM allows unauthenticated attackers with network access to modify critical data in Java deployments that run untrusted code, such as sandboxed Java Web St...

CVE-2023-21930

HIGH CVSS 7.4 Apr 18, 2023

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition's JSSE component allows attackers to compromise confidentiality and integrity of data via TLS connections. It affects Java deploymen...

CVE-2022-25647

HIGH CVSS 7.7 May 1, 2022

CVE-2022-25647 is a deserialization vulnerability in Google's Gson library versions before 2.8.9. Attackers can exploit the writeReplace() method in internal classes to cause denial of service (DoS) a...

CVE-2022-21476

HIGH CVSS 7.5 Apr 19, 2022

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated remote attackers to access sensitive data from Java applications. It affects Java deployments running sandbox...

CVE-2022-21449

HIGH CVSS 7.5 Apr 19, 2022

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated attackers with network access to modify critical data without authorization. It affects Java deployments runn...

CVE-2021-44531

HIGH CVSS 7.4 Feb 24, 2022

This vulnerability in Node.js allows attackers to bypass certificate name constraints by using arbitrary Subject Alternative Name (SAN) types, particularly URI SANs. It affects Node.js applications th...

CVE-2021-37712

HIGH CVSS 8.2 Aug 31, 2021

This vulnerability in the npm tar package allows attackers to bypass symlink checks by exploiting Unicode normalization and Windows short path behavior. It enables arbitrary file creation/overwrite an...

CVE-2021-39134

HIGH CVSS 8.2 Aug 31, 2021

This vulnerability in @npmcli/arborist allows attackers to write arbitrary files to any location on case-insensitive filesystems by exploiting case-sensitivity conflicts in dependency names. Anyone us...

CVE-2021-22940

HIGH CVSS 7.5 Aug 16, 2021

CVE-2021-22940 is a use-after-free vulnerability in Node.js that allows memory corruption attacks. An attacker could exploit this to potentially execute arbitrary code or crash the Node.js process. Th...

CVE-2021-32804

HIGH CVSS 8.2 Aug 3, 2021

The npm tar package before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has an arbitrary file creation/overwrite vulnerability due to insufficient sanitization of absolute paths. Attackers can create or o...

CVE-2021-3450

HIGH CVSS 7.4 Mar 25, 2021

This OpenSSL vulnerability allows certificate chain validation to be bypassed when the X509_V_FLAG_X509_STRICT flag is explicitly set. It affects applications using OpenSSL 1.1.1h-1.1.1j that enable s...

CVE-2021-22883

HIGH CVSS 7.5 Mar 3, 2021

Node.js servers are vulnerable to denial of service attacks when attackers establish numerous connections with unknown protocols, causing file descriptor leaks. This can exhaust system resources, prev...

CVE-2025-53057

MEDIUM CVSS 5.9 Oct 21, 2025

This vulnerability in Oracle Java SE and GraalVM allows an unauthenticated attacker with network access to potentially modify critical data through difficult-to-exploit attacks. It affects multiple Ja...

CVE-2025-30698

MEDIUM CVSS 5.6 Apr 15, 2025

This vulnerability in Oracle Java SE and GraalVM's 2D component allows an unauthenticated attacker with network access to potentially compromise Java deployments. It primarily affects clients running ...

CVE-2024-21145

MEDIUM CVSS 4.8 Jul 16, 2024

This vulnerability in Oracle Java SE's 2D component allows unauthenticated attackers with network access to potentially modify or read some accessible data. It affects multiple Java versions and Graal...