CVE-2026-22020

Public on 2026-04-27
Modified on 2026-04-27
Description
Updated libpng in Oracle Java. This CVE addresses a vulnerability in the bundled libpng library within Oracle's proprietary Java SE binary distribution. OpenJDK-based distributions that use the system libpng library are not affected.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core java-1.7.0-openjdk Not Affected
Amazon Linux 2 - Corretto8 Extra java-1.8.0-amazon-corretto Not Affected
Amazon Linux 2023 java-1.8.0-amazon-corretto Not Affected
Amazon Linux 2 - Core java-1.8.0-openjdk Not Affected
Amazon Linux 2 - Core java-11-amazon-corretto Not Affected
Amazon Linux 2023 java-11-amazon-corretto Not Affected
Amazon Linux 2 - Java-openjdk11 Extra java-11-openjdk Not Affected
Amazon Linux 2 - Core java-17-amazon-corretto Not Affected
Amazon Linux 2023 java-17-amazon-corretto Not Affected
Amazon Linux 2023 java-21-amazon-corretto Not Affected
Amazon Linux 2023 java-22-amazon-corretto No Fix Planned
Amazon Linux 2023 java-23-amazon-corretto No Fix Planned
Amazon Linux 2023 java-24-amazon-corretto Not Affected
Amazon Linux 2023 java-25-amazon-corretto Not Affected
Amazon Linux 2023 java-26-amazon-corretto Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H