Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian OpenJDK DSA-6110-1 Critical Cert Validation Man-in-the-Middle Attack

debian
Calendar Grey January 25, 2026
Debian Logo
OpenJDK security fixes address vulnerabilities including certificate validation and CRLF injection risks in Debian.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks

Summary

For the oldstable distribution (bookworm), these problems have been fixed
in version 17.0.18+8-1~deb12u1.

We recommend that you upgrade your openjdk-17 packages.

For the detailed security status of openjdk-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/openjdk-17

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: openjdk-17
CVE ID: CVE-2026-21925 CVE-2026-21932 CVE-2026-21933

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here