


Perceptive Security
SOC/SIEM Consultancy

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
Published:
4 May 2026 at 22:00:00
Alert date:
5 May 2026 at 21:02:16
Source:
nvd.nist.gov
Enterprise Applications
Eclipse OpenJ9 versions 0.21 to 0.58 contain a vulnerability where a pre-authentication remote attacker can crash the JITServer component by sending a specially crafted 32-byte TCP message. This denial of service vulnerability affects multiple versions of the OpenJ9 JVM implementation and can be exploited remotely without authentication. The vulnerability has been documented and patches are available through GitHub security advisories.
Technical details
Mitigation steps:
Affected products:
Eclipse OpenJ9
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6918
https://github.com/eclipse-openj9/openj9/pull/23793
https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-q393-vr4c-969r
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
