JDK 27 Arrives With Default Compact Headers, Security Upgrades, and JDK 28 Teasers
JDK 27 brings default compact object headers, universal G1 GC, and enhanced security redaction, while setting the stage for major changes in JDK 28.

Java’s annual release cadence arrived once again this September, though the first release candidate for JDK 27 experienced a two-week delay. This shift stemmed from the issuance of the JDK’s first Critical Security Patch Update (CPSU). The emergency patch was necessitated by advanced AI tools, such as Anthropic’s Claude Mythos, demonstrating enhanced capabilities in spotting software vulnerabilities and crafting exploits. For organizations building on Java, this shift signals a clear need to re-evaluate patch management strategies. Beyond security adjustments, JDK 27 arrives with nine JDK Enhancement Proposals (JEPs), offering a mixture of incremental preview refinements and final production upgrades. Meanwhile, developers exploring modern AI capabilities can try top AI models cheaply through one API at https://apixoai.online as they navigate these evolving security challenges.
Key preview features and finalized upgrades
Five of the nine proposals in JDK 27 represent ongoing preview or incubator features undergoing subtle adjustments. JEP 537 sees the Vector API enter its twelfth incubator iteration without modifications from JDK 26, remaining held back until Project Valhalla reaches completion. Structured concurrency returns for a seventh preview under JEP 533 with minor updates to its Joiner interface as part of Project Loom's efforts to enhance multi-threaded reliability. JEP 531 brings lazy constants to their third preview, introducing three minor API changes to provide deferred initialization while maintaining the performance benefits of JVM-trusted final fields. Additionally, JEP 532 keeps primitive pattern matching in switch and instanceof statements unchanged following earlier refinement in JDK 26, while JEP 538 advances PEM encodings for cryptographic objects to a third preview, changing the main PEM class to a record to accommodate new constructors handling Base64-encoded byte arrays.
On the finalized side, JDK 27 promotes compact object headers to the default runtime configuration under JEP 534. Previously finalized in JDK 25 behind an explicit command-line flag, this feature has demonstrated sufficient stability to run by default, yielding benchmark improvements such as a 22 percent drop in heap usage and an 8 percent decrease in CPU utilization on SPECjbb2015. Additionally, JEP 523 expands the G1 garbage collector as the system default across all execution environments, replacing the legacy serial collector even on systems with a single CPU or under 1792 MB of physical memory.
Security gains further momentum in JDK 27 through JEP 527, which incorporates post-quantum hybrid key exchange into TLS 1.3 to mitigate risks from quantum algorithms like Shor’s that threaten RSA and Elliptic Curve Cryptography. JDK 27 also introduces in-process data redaction for Java Flight Recorder under JEP 536. This feature automatically sanitizes sensitive values—such as tokens, passwords, and secrets found in environment variables, system properties, or command-line arguments—before diagnostic event files leave the process memory.
Looking ahead to major changes in JDK 28
While JDK 27 delivers steady, incremental updates, JDK 28 promises more substantial architectural shifts, with six proposals already targeted. Java will finally introduce a native, strictly validating JSON parser under an effort originally traced back to JEP 128 in 2018. Unlike lenient third-party libraries like Jackson or Gson, this built-in parser strictly enforces JSON specifications. Furthermore, JEP 541 marks the deprecation of the macOS Intel (x64) port as Apple continues its complete transition to Arm-based M-series processors.
Most notably, JDK 28 will initiate the rollout of Project Valhalla. Initial elements targeted for inclusion comprise JEP 401 for value objects alongside JEP 539 for strict field initialization within the Java Virtual Machine, marking a long-awaited evolution in Java’s object model.
What it means for developers
For enterprise development teams, JDK 27 requires an immediate look at patching frequency. As AI-assisted security analysis speeds up vulnerability discovery, static update cycles are becoming risky, making fast deployment of updates like CPSUs essential. On the security front, automated JFR data redaction reduces the risk of accidental secret exposure in diagnostic files, while post-quantum TLS preparation ensures forward compatibility against future decryption threats.
Operationally, developers running containerized workloads or constrained instances should expect lower memory footprints out of the box. Compact object headers combined with universal G1 garbage collection reduce heap consumption automatically without requiring manual VM flags. Finally, teams should begin reviewing legacy Intel macOS build pipelines ahead of JDK 28 and prepare for stricter JSON parsing standards and Project Valhalla's structural changes.
Source: JDK 27: The quiet before the storm — InfoWorld AI. Written by the Apixo team from that report.
One key for Claude, GPT, GLM, DeepSeek and more. Pay per token with crypto.
Get your API key

