Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-6038-1 OpenJDK 17 Important XML XXE/XEE Attack Risks

debian
Calendar Grey October 25, 2025
Debian Logo
Critical OpenJDK vulnerabilities fixed in Debian. Upgrade now to secure against XML XXE/XEE attacks.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in XML XXE/XEE attacks or incorrect certificate validation

Summary

For the oldstable distribution (bookworm), these problems have been fixed
in version 17.0.17+10-1~deb12u1.

We recommend that you upgrade your openjdk-17 packages.

For the detailed security status of openjdk-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/openjdk-17

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: openjdk-17
CVE ID: CVE-2025-53057 CVE-2025-53066

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here