Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 Bitnami
Not in CISA KEV

CVE-2026-47058 — java

CVE-2026-47058 is a Deserialization of Untrusted Data vulnerability in java. A fix is available for java — see the affected versions and patch details below.

Also known asBIT-java-min-2026-47058BIT-jre-2026-47058
Published
Aug 17, 2026
Updated
Sep 8, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-47058.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs30th percentile — riskier than 30% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

1 pkg affected
📦java

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Bitnami packages — download data is not available via public APIs for these ecosystems.

Description

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦Bitnamijava≥ 1.9.0&&< 1.8.01.8.0

Affected Products

2 products · 6 configurations
Application
jdkoracle
2 versions
1.8.011.0.31
Application
jreoracle
2 versions
1.8.011.0.31

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for java, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update java to 1.8.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-47058 is resolved across your whole dependency graph.

  3. Workarounds

    Do not deserialise data from untrusted sources: where the format allows it, restrict deserialisation to an explicit allowlist of expected types, and prefer a data-only format (JSON, Protobuf) over one that can reconstruct arbitrary objects until you can upgrade.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant
ProductFixed inAdvisory
OPENJDK ELS 11.0.32java-11-openjdk-portableRHSA-2026:42881
OPENJDK ELS 11.0.32java-11-openjdk-windowsRHSA-2026:42882
Red Hat Enterprise Linux 7 Extended Lifecycle Supportjava-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el7_9RHSA-2026:42876
Red Hat Enterprise Linux 8java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el8RHSA-2026:42877
Red Hat Enterprise Linux 8java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10RHSA-2026:52949
Red Hat OpenJDK 11 els for RHEL 7java-11-openjdk-1:11.0.32.0.9-1.el7_9RHSA-2026:42880

Frequently Asked Questions

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by
O3 Security · Impact-Aware SCA

Is CVE-2026-47058 in your dependencies?

Find it across Bitnami, including transitive dependencies.

CVE-2026-47058: java | O3 Security