CVE-2026-12856
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/06/2026
Last modified:
15/07/2026
Description
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://access.redhat.com/errata/RHSA-2026:36820
- https://access.redhat.com/security/cve/CVE-2026-12856
- https://bugzilla.redhat.com/show_bug.cgi?id=2491278
- https://github.com/redhat-developer/vscode-java/security/advisories/GHSA-7qv8-6qrw-3crv
- https://access.redhat.com/errata/RHSA-2026:36820
- https://access.redhat.com/security/cve/CVE-2026-12856
- https://bugzilla.redhat.com/show_bug.cgi?id=2491278
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12856.json



