Java Cup
Inside Java

News and views from members of the Java team at Oracle

Episode 71 “Security in Java” [AtA]

Posted on September 24, 2026

Given how prevalent Java is on web servers throughout the internet, security in Java is of critical importance. There's the security of the JDK itself, of course, which is overseen by the OpenJDK Security Group, which you should report JDK vulnerabilities to. But there are also the algorithms and features Java offers applications that are built on top of it and the cryptographic road map is an essential part of that development process. In recent years, post-quantum encryption has made big splashes but Java now also supports PEM texts and is considering the adoption of Argon2.

In this "Ask the Architects" episode of the Inside Java Podcast, recorded during JavaOne 2026, Nicolai Parlog talks to Sean Mullan, Lead of the OpenJDK Security Group and Tech Lead of the Oracle Security Libraries Team.

Show Notes

Additional Resources

In our show "Ask the Architects", we talk to experts in OpenJDK about their work on the Java language, API, and runtime. For Inside Java Podcast episodes, check out the podcast page or our YouTube playlist. For more Java news, subscribe to our RSS feed and follow @Java on X.

Contact us.