VYPR

Openj9

by Eclipse Openj9

Source repositories

CVEs (2)

  • CVE-2026-6918HigMay 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

  • CVE-2023-2597HigMay 22, 2023
    risk 0.00cvss 7.0epss 0.00

    In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.