logo

Tenable Discovers SSRF Vulnerability in Java TLS Handshakes That Creates DoS Risk

ID: d31b32a3-0927-5b50-bae3-41830a3c64c4

STIX ID: report--d31b32a3-0927-5b50-bae3-41830a3c64c4

Feed Name: Tenable Blog

Threat Score
60/100

Date Published: 2026-01-20

Date Updated: 2026-05-01

Author: Ireneusz Pastusiak

...
...

Tenable Research disclosed a Server-Side Request Forgery (SSRF) vulnerability in Java's TLS client-certificate handling where AIA CA Issuers URIs supplied in client certificates can cause the server to fetch attacker-controlled or local resources, leading to denial-of-service in mTLS setups; Oracle patched the issue as CVE-2026-21945 in January 2026 and administrators using Java mTLS with AIA fetching are advised to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.