Release date: July 21, 2026
The full version string for this update release is 25.0.4+7 (where "+" means "build"). The version number is 25.0.4. This JDK conforms to version 25 of the Java SE Specification (JSR 400 2025-09-16).
JDK 25.0.4 contains IANA time zone data 2026b which contains the following changes:
For more information, refer to Timezone Data Versions in the JRE Software.
The security baselines for the Java Runtime Environment (JRE) at the time of the release of JDK 25.0.4 are specified in the following table:
| JRE Family Version | JRE Security Baseline (Full Version String) |
|---|---|
| 25 | 25.0.4+7 |
| 21 | 21.0.12+7 |
| 17 | 17.0.20+7 |
| 11 | 11.0.32+7 |
| 8 | 1.8.0_501-b08 |
Oracle recommends that the JDK is updated with each Critical Patch Update. In order to determine if a release is the latest, the Security Baseline page can be used to determine which is the latest version for each release family.
Critical patch updates, which contain security vulnerability fixes, are announced one year in advance on Critical Patch Updates, Security Alerts and Bulletins. It is not recommended that this JDK (version 25.0.4) be used after the next Critical Security Patch Update scheduled for August 18, 2026. Oracle is transitioning to more frequent security updates, see the recently published blog for more information.
Java Management Service, available to all users, can help you find vulnerable Java versions in your systems. Java SE Subscribers and customers running in Oracle Cloud can use Java Management Service to update Java Runtimes and to do further security reviews like identifying potentially vulnerable third party libraries used by your Java programs. Existing Java Management Service user click here to log in to your dashboard. The Java Management Service Documentation provides a list of features available to everyone and those available only to customers. Learn more about using Java Management Service to monitor and secure your Java Installations.
The JDK now encodes ML-KEM and ML-DSA private keys in PKCS #8 format using the DER-encoded ASN.1 CHOICE formats defined in Section 6, "Private Key Format" of RFC 9935 and Section 6, "Private Key Format" of RFC 9881. Two new security properties, jdk.mlkem.pkcs8.encoding and jdk.mldsa.pkcs8.encoding, control the encoding used when generating new keys with a KeyPairGenerator or when translating keys with a KeyFactory. Valid values are seed, expandedKey, and both (case-insensitive). If a system property of the same name is also specified, it supersedes the security property value. All three formats are supported when decoding previously encoded private keys with a KeyFactory.
When these algorithms were introduced in JDK 24, the encoding format was equivalent to the expandedKey value. This release changes the default value to seed. As a result, ML-KEM and ML-DSA private keys generated by this JDK release will not be accepted by older releases by default, although keys generated by older releases are still readable by this release. To enable older JDK releases to accept ML-KEM and ML-DSA private keys generated by this JDK release, set the jdk.mlkem.pkcs8.encoding or jdk.mldsa.pkcs8.encoding property (whichever property is relevant to your use case) to expandedKey, and use KeyFactory.translateKey to convert the key to the older format.
The following root certificates have been added to the cacerts truststore:
+ WISeKey
+ wisekeyglobalrootgbca
DN: CN=OISTE WISeKey Global Root GB CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH
+ WISeKey
+ wisekeyglobalrootgcca
DN: CN=OISTE WISeKey Global Root GC CA, OU=OISTE Foundation Endorsed, O=WISeKey, C=CH
The DTLS implementation in the SunJSSE security provider has been enhanced to generate HelloVerifyRequest cookies as recommended by RFC 6347. To use this feature, applications must create the SSLEngine with the SSLContext.createSSLEngine(String peerHost, int peerPort) API.
A new management interface, jdk.management.HotSpotAOTCacheMXBean, has been added to the jdk.management module to provide the operation endRecording(). This operation ends the AOT recording and creates the AOT cache and/or configuration file. As with any MXBean, the operation can be invoked either from within the application or from an external tool such as jconsole.
The JFR event jdk.OldObjectSample is disabled when using generational ZGC.
The combination results in unacceptable performance overhead because the implementation relies on weak handles that, in generational ZGC, are processed only in the old generation.
A new jcmd diagnostic command, AOT.end_recording, has been introduced to end an in-progress ahead-of-time (AOT) training and record the results in the file or files specified by -XX:AOTConfiguration or -XX:AOTCacheOutput.
Note that the JVM must be started in AOT training mode using command-line options such as -XX:AOTMode=record or -XX:AOTCacheOutput=<file>. The results of the AOT training can be an AOT configuration file, an AOT cache file, or both. For more information about AOT training, see JEP 483: Ahead-of-Time Class Loading & Linking and JEP 514: Ahead-of-Time Command-Line Ergonomics.
A new system and security property, com.sun.security.crl.maxSize, has been added to limit the maximum length of a CRL that is downloaded through URIs in the CRL Distribution Points certificate extension during path validation. The value of these properties is the size in bytes of the DER-encoded CRL. For protocols that can return multivalue responses, such as LDAP, the size threshold is the sum of all CRLs downloaded from a single search query. CRLs that exceed this length will not be processed during certificate path validation. This size limit does not apply to CRLs that are imported through non-network-based means. A negative value disables this size limitation. A non-numeric value will be ignored, and the default size will be used instead. The default size limit is 20 MiB. For cases where both the security and system properties are set, the system property takes precedence. Enabling certificate path logging by setting java.security.debug=certpath will output the current size limit and note any discarded CRLs.
This release also contains fixes for security vulnerabilities described in the Oracle Critical Patch Update.
➜ Issues fixed in 25.0.4:| # | JBS | Component/Subcomponent | Summary |
|---|---|---|---|
| 1 | JDK-8369561 | client-libs/2d | sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000) |
| 2 | JDK-8378201 | client-libs/2d | [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable |
| 3 | JDK-8378417 | client-libs/2d | Printing All pages results in NPE for 1.1 PrintJob |
| 4 | JDK-8375057 | client-libs/2d | Update HarfBuzz to 12.3.2 |
| 5 | JDK-8297191 | client-libs/2d | [macos] Printing a page range with starting page > 1 results in missing pages |
| 6 | JDK-8376233 | client-libs/java.awt | Clean up code in Desktop native peer |
| 7 | JDK-8378727 | client-libs/java.awt | [macOS] Missing dispatch_release for semaphores in CDesktopPeer |
| 8 | JDK-8379256 | client-libs/java.awt | Update GIFlib to 6.1.1 |
| 9 | JDK-8380959 | client-libs/java.awt | Update Libpng to 1.6.56 |
| 10 | JDK-8380078 | client-libs/java.awt | Update GIFlib to 6.1.2 |
| 11 | JDK-8382047 | client-libs/java.awt | Update Libpng to 1.6.57 |
| 12 | JDK-8377526 | client-libs/java.awt | Update Libpng to 1.6.55 |
| 13 | JDK-8286258 | client-libs/javax.accessibility | [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially |
| 14 | JDK-8374506 | client-libs/javax.swing | Incorrect positioning of arrow icon in parent JMenu in Windows L&F |
| 15 | JDK-8365379 | client-libs/javax.swing | SU3.applyInsets may produce wrong results |
| 16 | JDK-8377727 | client-libs/javax.swing | Ghost caret and focus appear in non‑editable text fields |
| 17 | JDK-8365625 | client-libs/javax.swing | Can't change accelerator colors in Windows L&F |
| 18 | JDK-8376031 | core-libs/java.net | HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method |
| 19 | JDK-8369050 | core-libs/java.text | DecimalFormat Rounding Errors for Fractional Ties Near Zero |
| 20 | JDK-8365065 | core-libs/java.util.concurrent | Cancelled ForkJoinPool tasks no longer throw CancellationException |
| 21 | JDK-8371294 | core-libs/java.util.jar | JAR File Specification page typography issue |
| 22 | JDK-8374644 | core-libs/java.util.jar | Regression in GZIPInputStream performance after JDK-7036144 |
| 23 | JDK-8378631 | core-libs/java.util.jar | Update Zlib Data Compression Library to Version 1.3.2 |
| 24 | JDK-8362428 | core-libs/java.util:i18n | Update IANA Language Subtag Registry to Version 2025-08-25 |
| 25 | JDK-8384043 | core-libs/java.util:i18n | [REDO] Incorrect handling of Hawaii_Aleutian metazone |
| 26 | JDK-8382020 | core-libs/java.util:i18n | Time Zone Abbreviation Not Localized for Non-English Locales |
| 27 | JDK-8371864 | hotspot/compiler | GaloisCounterMode.implGCMCrypt0 AVX512/AVX2 intrinsics stubs cause AES-GCM encryption failure for certain payload sizes |
| 28 | JDK-8376104 | hotspot/compiler | C2 crashes in PhiNode::Ideal(PhaseGVN*, bool) accessing NULL pointer |
| 29 | JDK-8373894 | hotspot/gc | G1: Count evacuation-failed garbage collections in gc cpu usage |
| 30 | JDK-8382242 | hotspot/jfr | JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String |
| 31 | JDK-8371320 | hotspot/runtime | runtime/ErrorHandling/PrintVMInfoAtExitTest.java fails with unexpected amount for Java Heap reserved memory |
| 32 | JDK-8380474 | hotspot/runtime | Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792 |
| 33 | JDK-8377932 | hotspot/runtime | AOT cache is not rejected when JAR file has changed |
| 34 | JDK-8357086 | hotspot/runtime | os::xxx functions returning memory size should return size_t |
| 35 | JDK-8377512 | hotspot/runtime | AOT cache creation fails with invalid native pointer |
| 36 | JDK-8380409 | hotspot/runtime | JVM crashes when -XX:AOTMode=create uses app.aotconf generated with JVMTI agent |
| 37 | JDK-8363986 | hotspot/runtime | Heap region in CDS archive is not at deterministic address |
| 38 | JDK-8323792 | hotspot/svc | ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer) |
| 39 | JDK-8365057 | hotspot/svc | Add support for java.util.concurrent lock information to Thread.dump_to_file |
| 40 | JDK-8373690 | security-libs/java.security | Unexpected Keystore message using jdk.crypto.disabledAlgorithms |
| 41 | JDK-8373928 | tools/launcher | 4 Dangling pointer defect groups in java.c |