Description
In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.
In plain language
AI Worth attentionEclipse OpenJ9 versions before 0.60 can be crashed by a specially made Java file, so small businesses using it should update.
A crafted .class file with deeply nested annotations triggers a CWE-674 uncontrolled-recursion condition that can cause a segmentation fault in Eclipse OpenJ9.
What to do now
- Check whether your Java applications or runtime use Eclipse OpenJ9 and identify the installed version.
- Update Eclipse OpenJ9 to version 0.60.
- Until updated, do not process untrusted .class files in affected applications.
Weaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-16440 and every CVE in our database. Create a free account — no credit card required.
Create Free Account