SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
Java New Added 8 September 2026

Java: PKIX path building failed, unable to find valid certification path

The JVM could not build a trust chain to the server's certificate. Java keeps its own truststore rather than using the operating system's, so a private or corporate CA that curl accepts is unknown to Java until it is imported.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# See the chain the server sends
openssl s_client -connect api.internal:443 -showcerts </dev/null

# Import the root into the JDK truststore
keytool -importcert -alias corp-root -file corp-root.crt \
  -cacerts -storepass changeit

# Or use an application truststore, which survives JDK upgrades
keytool -importcert -alias corp-root -file corp-root.crt \
  -keystore app-truststore.jks -storepass secret
java -Djavax.net.ssl.trustStore=app-truststore.jks \
     -Djavax.net.ssl.trustStorePassword=secret -jar app.jar

# Debug what the JVM is trying
java -Djavax.net.debug=ssl:handshake:trustmanager -jar app.jar

How to diagnose Java errors

Java errors concentrate at the class loading boundary (ClassNotFoundException, NoClassDefFoundError, UnsupportedClassVersionError) and around resource pools under load. Class loading errors are almost always classpath or version problems rather than missing code. UnsupportedClassVersionError in particular is a pure bytecode-version mismatch and tells you exactly which JDK compiled the class.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Print the actual runtime version with java -version and compare it against your build target. Major bytecode version 65 is Java 21, 61 is Java 17, 52 is Java 8.
  2. Inspect the resolved dependency tree (mvn dependency:tree, gradle dependencies) to find duplicate or conflicting versions of the same library.
  3. For pool exhaustion, log pool metrics (HikariCP exposes active, idle and pending counts). Exhaustion means connections are not being returned, which is a try-with-resources problem.
  4. Enable -verbose:class temporarily to see which jar a class is loaded from when two versions are on the classpath.
  5. Capture a heap dump on OOM with -XX:+HeapDumpOnOutOfMemoryError and analyse it rather than raising -Xmx blindly.

Tools worth reaching for

  • mvn dependency:tree
  • jcmd / jstack / jmap
  • -verbose:class
  • Eclipse MAT
  • JFR (Java Flight Recorder)

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

docs.oracle.com

Related Java errors

See all 19 Java errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.