After JDK-8282429 (19) certain Strings built using StringBuilder return an incorrect result for String.equals() checks.
OpenJDK-21 upstream commit: https://github.com/openjdk/jdk21u/commit/23bd6b50dbbf33975c21c122f8b7e4c7b0d57fdc
This CVE was fixed in Oracle Java SE 21.0.9, 25.0.1. https://www.oracle.com/java/technologies/javase/21-0-9-relnotes.html https://www.oracle.com/java/technologies/javase/25-0-1-relnotes.html