CVE-2026-22013 is a vulnerability in the JGSS component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Affected supported versions are Oracle Java SE 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26; Oracle GraalVM for JDK 17.0.18 and 21.0.10; and Oracle GraalVM Enterprise Edition 21.3.17. An unauthenticated attacker with network access through multiple protocols can exploit the vulnerability with interaction from another person to obtain unauthorized access to critical data or all data accessible to the affected runtime. Exploitation is described as difficult. The vulnerability applies to deployments that execute untrusted code and rely on the Java sandbox for security, typically sandboxed Java Web Start applications or Java applets. Deployments that execute only trusted code are not affected. The underlying implementation defect and vulnerable function are not specified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2026-22013, a stack-based buffer overflow in a hardware wallet USB descriptor parsing routine. The repository contains only three files: an MIT LICENSE, a README describing the issue and build/run steps, and a single C source file (hw_wallet_usb.c) implementing the vulnerable logic and a local trigger. The core function, handle_usb_setup(), allocates a 32-byte stack buffer named descriptor and, when the first byte of input equals USB GET_DESCRIPTOR (0x06), copies len-1 bytes from data+1 into that buffer using memcpy() without validating length. The main() function constructs a 64-byte malicious buffer, fills it with 'A', sets the first byte to 0x06, and calls the vulnerable function, causing stack corruption. There are no network, web, or command-and-control capabilities, no shell payload, and no post-exploitation logic. The code is a standalone local/physical USB memory-corruption demonstration rather than a weaponized exploit. The only fingerprintable target indicator in the code is the USB request selector GET_DESCRIPTOR (0x06) and the referenced source file path; no URLs, IPs, domains, registry keys, or external endpoints are present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability referenced by an Alma Linux 9.2 TuxCare security update; no technical vulnerability details are provided.
A vulnerability covered by the referenced CentOS 7 TuxCare security advisory; no technical vulnerability details are provided.
A vulnerability referenced by the CentOS 6 TuxCare security-check advisory; no technical details are provided in the content.
A vulnerability referenced as addressed by the TuxCare CentOS 7 security update; no technical flaw details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.