There is a CRLF injection vulnerability in HttpServer in JDK which may lead to potential XSS.
This issue has been addressed in the following products: OPENJDK ELS 11.0.30 Via RHSA-2026:0849 https://access.redhat.com/errata/RHSA-2026:0849