Oracle Launches Java 27 Featuring Hybrid Post-Quantum Cryptography for TLS 1.3
quantumcomputingreport.com Sep 17, 2026

Oracle Launches Java 27 Featuring Hybrid Post-Quantum Cryptography for TLS 1.3

AI-summarised brief · reviewed before publication

Oracle announced the general availability of Java 27 (Oracle JDK 27), emphasizing enterprise‑grade post‑quantum cryptography (PQC) to counter “harvest now, decrypt later” threats. The release introduces JEP 527, which embeds hybrid key‑exchange algorithms into the javax.net.ssl API, pairing classical TLS 1.3 key exchange with quantum‑resistant encapsulation mechanisms and providing default quantum protection without code changes. Oracle also added Oracle Jipher 20 to the Java Verified Portfolio, a FIPS 140‑3 validated OpenSSL module supporting NIST‑standardized ML‑KEM (Kyber) and ML‑DSA (Dilithium) algorithms. Additional updates include JEP 538 for PEM encoding previews, JEP 534’s compact object headers to shrink heap usage, and JEP 523 making G1 the default garbage collector. Oracle plans to backport comparable PQC features to its long‑term support Java releases.

💡 Why It Matters

  • · By integrating quantum‑resistant TLS directly into Java’s core APIs, Oracle gives developers immediate protection against future decryption attacks, accelerating industry‑wide PQC adoption.