There is a CRLF injection vulnerability in HttpServer in JDK which may lead to potential XSS.
This issue has been addressed in the following products: OPENJDK ELS 11.0.30 Via RHSA-2026:0849 https://access.redhat.com/errata/RHSA-2026:0849
This issue has been addressed in the following products: Red Hat OpenShift Lightspeed Via RHSA-2026:1070 https://access.redhat.com/errata/RHSA-2026:1070 https://coolgamesonline.io
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:0931 https://access.redhat.com/errata/RHSA-2026:0931
OpenJDK-8 upstream commit: https://github.com/openjdk/jdk8u/commit/332d177c5504e067406c604045d8748a1d696fc9 OpenJDK-11 upstream commit: https://github.com/openjdk/jdk11u/commit/8eaf265cc43bf93a0e0b837d87a774d317abc07c OpenJDK-17 upstream commit: https://github.com/openjdk/jdk17u/commit/8a0c7db0c59883dc6b93870087a501bde671a582 OpenJDK-21 upstream commit: https://github.com/openjdk/jdk21u/commit/f744c46f5f3c52cbaf7d46faff348dc0a2b9054c OpenJDK-25 upstream commit: https://github.com/openjdk/jdk25u/commit/10d48fee022cc09ea72fcc40056749062e5cebe0
This CVE was fixed in Oracle Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2. https://www.oracle.com/java/technologies/javase/8u481-relnotes.html#R180_481 https://www.oracle.com/java/technologies/javase/11-0-30-relnotes.html#R11_0_30 https://www.oracle.com/java/technologies/javase/17-0-18-relnotes.html#R17_0_18 https://www.oracle.com/java/technologies/javase/21-0-10-relnotes.html https://www.oracle.com/java/technologies/javase/25-0-2-relnotes.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4832 https://access.redhat.com/errata/RHSA-2026:4832