A client RMI TCP endpoint connects to the remote host without setting an endpoint identification algorithm which could allow MITM attacks.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:0931 https://access.redhat.com/errata/RHSA-2026:0931
OpenJDK-8 upstream commit: https://github.com/openjdk/jdk8u/commit/f858c7ab3bda7ed5a0babb8e8a29c5e08c640fec OpenJDK-11 upstream commit: https://github.com/openjdk/jdk11u/commit/eea83eed5e9f2cbb8ef003c6f54ffb22d5ea98c9 OpenJDK-17 upstream commit: https://github.com/openjdk/jdk17u/commit/2a6281a2293cf658902c5877b862e16bf02c949c OpenJDK-21 upstream commit: https://github.com/openjdk/jdk21u/commit/74ac53141464f5fc479786c82ff71bde0b46abe2 OpenJDK-25 upstream commit: https://github.com/openjdk/jdk25u/commit/5390df6b4a59207511b17a0fc87fc4adbd124b67
This CVE was fixed in Oracle Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2. https://www.oracle.com/java/technologies/javase/8u481-relnotes.html#R180_481 https://www.oracle.com/java/technologies/javase/11-0-30-relnotes.html#R11_0_30 https://www.oracle.com/java/technologies/javase/17-0-18-relnotes.html#R17_0_18 https://www.oracle.com/java/technologies/javase/21-0-10-relnotes.html https://www.oracle.com/java/technologies/javase/25-0-2-relnotes.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4832 https://access.redhat.com/errata/RHSA-2026:4832