Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws

IBM and Red Hat have found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, their program for patching open source code that companies already run in production.

Java library vulnerabilities

Companies running the affected libraries are exposed until they apply the fixes. Autonomous AI agents can now combine several minor software weaknesses into one serious attack.

“AI agents do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started,” said Gunnar Hellekson, VP and GM, Lightwell, Red Hat.

The two companies also made Lightwell Clearinghouse generally available, letting enterprise customers submit specific open source dependencies for priority review and repair.

How the fixes reach customers

Lightwell backports the patches. That means it rewrites each fix to fit the older library version a company still runs, so the team can apply it without first upgrading.

The patches arrive through secured repositories that plug into a customer’s existing scanners, software repositories, development pipelines and testing. Clearinghouse adds a request line: a customer names a vulnerability it cares about, and Lightwell reviews it, fixes it and supplies a patch for the older version in use.

No names, no CVEs, no severity scores

The companies didn’t say which libraries were affected. You won’t find CVE numbers, severity ratings or a time frame for the 400 finds either.

Red Hat says fixes that apply upstream go back to the open source projects through responsible disclosure, though Clearinghouse participants keep their embargo protections. So if you use these libraries and you’re not in the program, your fix will come from the public upstream release, whenever disclosure allows it.

Webinar: Closing the accountability gap in AI-assisted delivery

Don't miss