---
title: "CVE-2026-22013\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-22013?format=md
keywords: index, follow
---

# CVE-2026-22013

Publication date 21 April 2026

Last updated 2 June 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2026-22013?format=md#impact-score)

Toggle side navigation

## Description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM
Enterprise Edition product of Oracle Java SE (component: JGSS). Supported
versions that are affected are Oracle Java SE: 8u481, 8u481-b50,
8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK:
17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult
to exploit vulnerability allows unauthenticated attacker with network
access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM
for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require
human interaction from a person other than the attacker. Successful attacks
of this vulnerability can result in unauthorized access to critical data
or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle
GraalVM Enterprise Edition accessible data. Note: This vulnerability
applies to Java deployments, typically in clients running sandboxed Java
Web Start applications or sandboxed Java applets, that load and run
untrusted code (e.g., code that comes from the internet) and rely on the
Java sandbox for security. This vulnerability does not apply to Java
deployments, typically in servers, that load and run only trusted code
(e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3
(Confidentiality impacts). CVSS Vector:
(CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-13 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Ignored superseded by openjdk-17 |
| openjdk-16 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Ignored superseded by openjdk-17 |
| openjdk-17 | 26.04 LTS resolute | Fixed 17.0.19+10-1~26.04.2 |
| 25.10 questing | Fixed 17.0.19+10-1~25.10.2 |
| 24.04 LTS noble | Fixed 17.0.19+10-1~24.04.2 |
| 22.04 LTS jammy | Fixed 17.0.19+10-1~22.04.2 |
| 20.04 LTS focal | Fixed 17.0.19+10-1~20.04.2  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 17.0.19+10-1~18.04.2  Ubuntu Pro |
| openjdk-17-crac | 26.04 LTS resolute | Fixed 17.0.19+10-0ubuntu1~26.04.1 |
| 25.10 questing | Fixed 17.0.19+10-0ubuntu1~25.10.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| openjdk-18 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Ignored superseded by openjdk-19 |
| openjdk-21 | 26.04 LTS resolute | Fixed 21.0.11+10-1~26.04.2 |
| 25.10 questing | Fixed 21.0.11+10-1~25.10.2 |
| 24.04 LTS noble | Fixed 21.0.11+10-1~24.04.2 |
| 22.04 LTS jammy | Fixed 21.0.11+10-1~22.04.2 |
| 20.04 LTS focal | Fixed 21.0.11+10-1~20.04.2  Ubuntu Pro |
| openjdk-21-crac | 26.04 LTS resolute | Fixed 21.0.11+10-0ubuntu1~26.04.1 |
| 25.10 questing | Fixed 21.0.11+10-0ubuntu1~25.10.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| openjdk-25 | 26.04 LTS resolute | Fixed 25.0.3+9-2~26.04.2 |
| 25.10 questing | Fixed 25.0.3+9-2~25.10.2 |
| 24.04 LTS noble | Fixed 25.0.3+9-2~24.04.2 |
| 22.04 LTS jammy | Fixed 25.0.3+9-2~22.04.2 |
| openjdk-25-crac | 26.04 LTS resolute | Fixed 25.0.3+9-0ubuntu1~26.04.1 |
| 25.10 questing | Fixed 25.0.3+9-0ubuntu1~25.10.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| openjdk-26 | 26.04 LTS resolute | Fixed 26.0.1+8-2~26.04.2 |
| 25.10 questing | Fixed 26.0.1+8-2~25.10.2 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| openjdk-8 | 26.04 LTS resolute | Fixed 8u492-ga~us2-0ubuntu1~26.04.1 |
| 25.10 questing | Fixed 8u492-ga~us2-0ubuntu1~25.10.1 |
| 24.04 LTS noble | Fixed 8u492-ga~us2-0ubuntu1~24.04.1 |
| 22.04 LTS jammy | Fixed 8u492-ga~us2-0ubuntu1~22.04.1 |
| 20.04 LTS focal | Fixed 8u492-ga~us2-0ubuntu1~20.04.1  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 8u492-ga~us2-0ubuntu1~18.04.1  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 8u492-ga~us2-0ubuntu1~16.04.1  Ubuntu Pro |
| openjdk-9 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Ignored end of ESM support, was ignored [no longer supported by upstream] |
| openjdk-lts | 26.04 LTS resolute | Fixed 11.0.31+11-1ubuntu1~26.04.2 |
| 25.10 questing | Fixed 11.0.31+11-1ubuntu1~25.10.2 |
| 24.04 LTS noble | Fixed 11.0.31+11-1ubuntu1~24.04.2 |
| 22.04 LTS jammy | Fixed 11.0.31+11-1ubuntu1~22.04.2 |
| 20.04 LTS focal | Fixed 11.0.31+11-1ubuntu1~20.04.2  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 11.0.31+11-1ubuntu1~18.04.2  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-22013)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-22013)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-22013)

### Related Ubuntu Security Notices (USN)

+ [USN-8330-1](https://usn.ubuntu.com/USN-8330-1)
+ OpenJDK 8 vulnerabilities
+ 28 May 2026

+ [USN-8331-1](https://usn.ubuntu.com/USN-8331-1)
+ OpenJDK 11 vulnerabilities
+ 28 May 2026

+ [USN-8332-1](https://usn.ubuntu.com/USN-8332-1)
+ CRaC JDK 17 vulnerabilities
+ 28 May 2026

+ [USN-8333-1](https://usn.ubuntu.com/USN-8333-1)
+ CRaC JDK 21 vulnerabilities
+ 28 May 2026

+ [USN-8334-1](https://usn.ubuntu.com/USN-8334-1)
+ CRaC JDK 25 vulnerabilities
+ 28 May 2026

+ [USN-8327-1](https://usn.ubuntu.com/USN-8327-1)
+ OpenJDK 17 vulnerabilities
+ 28 May 2026

+ [USN-8328-1](https://usn.ubuntu.com/USN-8328-1)
+ OpenJDK 21 vulnerabilities
+ 28 May 2026

+ [USN-8341-1](https://usn.ubuntu.com/USN-8341-1)
+ OpenJDK 26 vulnerabilities
+ 28 May 2026

+ [USN-8339-1](https://usn.ubuntu.com/USN-8339-1)
+ OpenJDK 25 vulnerabilities
+ 28 May 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-22013>
* <https://openjdk.org/groups/vulnerability/advisories/2026-04-21>
