vulnerability

Ubuntu: (Multiple Advisories) (CVE-2025-53066): OpenJDK 8 vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Oct 21, 2025
Added
Nov 26, 2025
Modified
Dec 3, 2025

Description

Jinfeng Guo discovered that the Security component of OpenJDK 8 did not
correctly handle certain representations of encoded strings. An
unauthenticated remote attacker could possibly use this issue to modify
files or leak sensitive information. (CVE-2025-53057)

Darius Bohni discovered that the JAXP component of OpenJDK 8 was
vulnerable to a XML External Entity (XEE) attack. An unauthenticated
remote attacker could possibly use this issue to modify files or leak
sensitive information. (CVE-2025-53066)

In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:
https://openjdk.org/groups/vulnerability/advisories/2025-10-21

Solutions

ubuntu-upgrade-openjdk-11-jdkubuntu-upgrade-openjdk-11-jdk-headlessubuntu-upgrade-openjdk-11-jreubuntu-upgrade-openjdk-11-jre-headlessubuntu-upgrade-openjdk-11-jre-zeroubuntu-upgrade-openjdk-17-crac-jdkubuntu-upgrade-openjdk-17-crac-jdk-headlessubuntu-upgrade-openjdk-17-crac-jreubuntu-upgrade-openjdk-17-crac-jre-headlessubuntu-upgrade-openjdk-17-crac-jre-zeroubuntu-upgrade-openjdk-17-jdkubuntu-upgrade-openjdk-17-jdk-headlessubuntu-upgrade-openjdk-17-jreubuntu-upgrade-openjdk-17-jre-headlessubuntu-upgrade-openjdk-17-jre-zeroubuntu-upgrade-openjdk-21-crac-jdkubuntu-upgrade-openjdk-21-crac-jdk-headlessubuntu-upgrade-openjdk-21-crac-jreubuntu-upgrade-openjdk-21-crac-jre-headlessubuntu-upgrade-openjdk-21-crac-jre-zeroubuntu-upgrade-openjdk-21-jdkubuntu-upgrade-openjdk-21-jdk-headlessubuntu-upgrade-openjdk-21-jreubuntu-upgrade-openjdk-21-jre-headlessubuntu-upgrade-openjdk-21-jre-zeroubuntu-upgrade-openjdk-25-crac-jdkubuntu-upgrade-openjdk-25-crac-jdk-headlessubuntu-upgrade-openjdk-25-crac-jreubuntu-upgrade-openjdk-25-crac-jre-headlessubuntu-upgrade-openjdk-25-crac-jre-zeroubuntu-upgrade-openjdk-25-jdkubuntu-upgrade-openjdk-25-jdk-headlessubuntu-upgrade-openjdk-25-jreubuntu-upgrade-openjdk-25-jre-headlessubuntu-upgrade-openjdk-25-jre-zeroubuntu-upgrade-openjdk-8-jdkubuntu-upgrade-openjdk-8-jdk-headlessubuntu-upgrade-openjdk-8-jreubuntu-upgrade-openjdk-8-jre-headlessubuntu-upgrade-openjdk-8-jre-jamvmubuntu-upgrade-openjdk-8-jre-zero

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.