Java 27 turns on post-quantum TLS and makes G1 the default collector
JDK 27 reached general availability on 15 September with nine JEPs, including hybrid post-quantum key exchange for TLS 1.3 and smaller object headers.
Oracle and the OpenJDK community released JDK 27, the newest version of Java, on 15 September 2026, according to Oracle's Inside.java site. It carries nine JDK Enhancement Proposals. The main security change protects encrypted connections against future quantum computers, and it switches on in ordinary programs without any code change.
- 9JDK Enhancement Proposals in JDK 27
- 15 Sep 2026general availability date of JDK 27
- 16%of fixes contributed by independent developers
- March 2027end of Oracle updates for JDK 27
What happened
JDK 27 is the eighteenth Java release on the six-month schedule that Java has followed since 2018, and Oracle says it arrived on time. The OpenJDK project page shows the steps before release: the code branched in June, release candidates followed in August, and general availability came on 15 September. Each new feature is described in a JDK Enhancement Proposal, or JEP. Some JEPs are final, while others are previews or incubators that developers can test before the design is fixed.
Four of the nine changes are the most practical. JEP 527 adds post-quantum hybrid key exchange to TLS 1.3, the protocol that secures web and network connections. JEP 523 makes G1 the default garbage collector on every machine. JEP 534 turns on compact object headers by default. JEP 536 lets Java Flight Recorder, a built-in monitoring tool, hide sensitive data in its recordings. The other five are previews or incubators: lazy constants, primitive types in pattern matching, structured concurrency, PEM encoding of cryptographic keys, and the Vector API, now in its twelfth incubator round.
Oracle says it will provide updates for JDK 27 until March 2027, when JDK 28 replaces it. That short support period is normal for a non-long-term release. Inside.java also reported that independent developers wrote 16 percent of the fixes in this release, with notable work from companies including Alibaba, Amazon, ARM, Google, IBM, Microsoft, NVIDIA, Red Hat and SAP. Structured concurrency, which helps programs manage many tasks running at once, is now in its seventh preview, a sign of how slowly and carefully Java changes its core language.
The engineering behind it
Every secure connection begins with a key exchange, where two computers agree on a secret key without sending it in plain view. Today this usually relies on elliptic-curve mathematics. A large enough quantum computer could break that mathematics. The JEP explains the main worry: an attacker could record encrypted traffic now and decrypt it years later, once such machines exist. This is called harvest now, decrypt later. Encrypting the traffic itself, once the key is agreed, is a separate step that is less exposed to this risk.
JEP 527 answers this with a hybrid scheme. It combines ML-KEM, a quantum-resistant method standardised by the US standards body NIST, with the familiar X25519 elliptic-curve method. The connection stays safe as long as either method remains unbroken. That matters because ML-KEM is newer and less tested. The default group, X25519MLKEM768, is offered first by Java clients. Programs that use the standard javax.net.ssl package get it automatically, while code that already chooses its own groups keeps its old settings.
The memory changes are about efficiency. Every Java object carries a small header with information the virtual machine needs. On 64-bit systems, JEP 534 shrinks this header from 96 bits to 64 bits. Programs that create millions of small objects can save a noticeable amount of memory this way, and smaller objects also fit better in the processor's cache. In general, the cost of a smaller header is that the virtual machine must pack the same information into fewer bits, which needs careful design and testing.
A garbage collector is the part of the Java runtime that finds memory no longer in use and frees it. Java has several collectors. Until now the runtime chose the simple Serial collector on small machines and G1 on server-class machines. With JEP 523 it always picks G1 unless told otherwise. The JEP says throughput, delays, memory use and start-up time should not get significantly worse on machines that used Serial before.
What it means in Nepal
The sources say nothing about Nepal. The lesson for students is a general one. Post-quantum cryptography, which until recently appeared mostly in research papers and standards documents, is now switched on by default in a widely used programming platform. Any Java program that makes secure connections and moves to JDK 27 will start using it. Security engineers who understand what changed, and how to check which key exchange a connection is using, will be able to answer questions that clients and auditors are starting to ask.
There is also a practical point about versions. Organisations that run Java in production usually choose a long-term support release, such as JDK 21 or JDK 25, and stay on it for years. JDK 27 receives updates only until March 2027. A student learning Java should know the newest features but should expect real projects to use an older long-term version. Being able to read release notes and judge whether an upgrade is safe is a useful skill in any software job.
Finally, the compact headers and the change of default collector show that small technical details still matter. Saving 32 bits per object sounds tiny, but across millions of objects it reduces memory use. Understanding why that happens, and measuring it, is the kind of work that separates a programmer who writes code from an engineer who understands how it runs.
What to study if this interests you
Object Oriented Programming, ENCT 151, in the second semester of BCT and BEI, teaches classes and objects, the things whose headers JDK 27 shrinks. The course has a full guide on this site. Operating System, ENCT 254, in the fourth semester of BCT, explains memory management, which is the basis for understanding how a garbage collector works.
Network and Cyber Security, ENCT 463, in the eighth semester of BCT, covers encryption, key exchange and secure protocols such as TLS. It gives the background needed to see why a hybrid key exchange protects connections today against computers that may only exist in the future. Computer Networks, ENCT 304, in the fifth semester, shows where TLS sits among the layers of network protocols and what happens during a connection handshake.
Words in this story
- TLS
- Transport Layer Security, the protocol that encrypts web and network connections, shown by the padlock in a browser.
- Key exchange
- The first step of a secure connection, in which two computers agree on a shared secret key.
- Garbage collector
- The part of a language runtime that finds memory a program no longer uses and frees it automatically.
- Post-quantum cryptography
- Encryption methods designed to stay secure even against attackers who have large quantum computers.
Where this comes from
- Inside.java (Oracle), 15 Sep 2026
- OpenJDK, JDK 27 project page, 15 Sep 2026
- OpenJDK, JEP 527, 15 Sep 2026
Written in our own words; no sentence is copied from these reports. Researched with AI assistance on 11 October 2026; no member of faculty has reviewed it yet. If you spot a mistake, call 01-5091616 and we will correct it and say so.




