back to all blogsSee all blog posts

Java 27 Support in 26.0.0.10

image of author
Ismath Badsha on Oct 6, 2026
Post available in languages:

Open Liberty 26.0.0.10 adds support for Java 27.

In Open Liberty 26.0.0.10:

View the list of fixed bugs in 26.0.0.10.

Support for Java 27

Java 27 is the latest version of Java. It contains a few new features and enhancements over previous versions of Java that you need to review. This is not a Long-Term-Support (LTS) release.

There are 9 new features (JEPs) in Java 27. Five are test features and four are fully delivered:

Test features:

Delivered features:

An important note about JEP 523 — JEP 523 changes the default garbage collector in Java 27. The G1 garbage collector (GC) is now the default in all environments, including environments that previously used the Serial or Parallel GC, for example, single-CPU or low-memory environments such as containers. If you run Liberty in constrained environments, you might notice different GC behavior compared to earlier Java releases. To revert to the previous garbage collector, use -XX:+UseSerialGC or -XX:+UseParallelGC.

Try out the new changes now and get more time to preview your applications and microservices running with Java 27.

Download IBM Semeru Runtimes 27 or Java 27, download and install the 26.0.0.10, set JAVA_HOME to your Java 27 installation directory in your Liberty server’s server.env file, and start testing.

For more information about Java 27, see the Java 27 release notes page, Javadoc or download page. For more information about Open Liberty, see our documentation page.

Security vulnerability (CVE) fixes in this release

CVE CVSS Score Vulnerability Assessment Versions Affected Notes

CVE-2026-11713

5.4

Information disclosure

17.0.0.3-26.0.0.9

CVE-2026-14909

6.5

SQL injection

17.0.0.3-26.0.0.9

CVE-2026-49875

9.8

Server-side request forgery

17.0.0.3-26.0.0.9

Affects the jaxrs-2.0, jaxrs-2.1, jaxws-2.2, xmlWS-3.0, xmlWS-4.0, and wsAtomicTransaction-1.2 features

CVE-2026-65432

7.5

Cross-site scripting

17.0.0.3-26.0.0.9

Affects the jaxws-2.2, xmlWS-3.0, xmlWS-4.0, wsSecurity-1.1, and wsAtomicTransaction-1.2 features

CVE-2026-66142

7.5

Denial of service

17.0.0.3-26.0.0.9

Affects the jaxws-2.2, xmlWS-3.0, and xmlWS-4.0 features

CVE-2026-66143

7.5

Denial of service

17.0.0.3-26.0.0.9

Affects the jaxws-2.2, xmlWS-3.0, and xmlWS-4.0 features

CVE-2026-66144

7.5

Denial of service

17.0.0.3-26.0.0.9

Affects the jaxws-2.2, xmlWS-3.0, and xmlWS-4.0 features

For a list of past security vulnerability fixes, reference the Security vulnerability (CVE) list.

Develop and run your apps using 26.0.0.10

If you’re using Maven, include the following in your pom.xml file:

<plugin>
    <groupId>io.openliberty.tools</groupId>
    <artifactId>liberty-maven-plugin</artifactId>
    <version>3.12.3</version>
</plugin>

Or for Gradle, include the following in your build.gradle file:

buildscript {
    repositories {
        mavenCentral()
    }
    dependencies {
        classpath 'io.openliberty.tools:liberty-gradle-plugin:4.0.2'
    }
}
apply plugin: 'liberty'

Or if you’re using container images:

FROM icr.io/appcafe/open-liberty

Or take a look at our Downloads page.

If you’re using IntelliJ IDEA, Visual Studio Code or Eclipse IDE, you can also take advantage of our open source Liberty developer tools to enable effective development, testing, debugging and application management all from within your IDE.

Ask a question on Stack Overflow

Get Open Liberty 26.0.0.10 now