Skip to main content

HTTP/3 in the Java HTTP Client (JEP 517): Migrating from HttpClient 11

JEP 517 added HTTP/3 to java.net.http in Java 26 as an opt-in. What the opt-in looks like, how the three H3_DISCOVERY modes behave, what fallback costs in seconds, why proxies silently downgrade you, and how HTTP/1.1, HTTP/2 and HTTP/3 compare under simulated packet loss, all measured on a local server with captured transcripts.

How to Sort a HashMap by Value (and Key) in Java

The shortest correct way to sort a Java HashMap by value or key (stream into a LinkedHashMap), plus the traps: a TreeMap with a value comparator silently drops tied entries, top-N with a PriorityQueue measured against sort-and-limit in JMH, and JDK 21+ sequenced collections (reversed, firstEntry).

Java Serialization in 2026: Why It’s Dangerous and What Replaced It

Why ObjectInputStream.readObject() on untrusted bytes is dangerous, shown with harmless stand-ins: serialVersionUID drift, code that runs before your cast, and a 37-byte stream that asks for 1 GB. Then the JDK's answer (JEP 290 filters, JEP 415 filter factories), records, and a measured size and speed comparison with Jackson 3 and Protobuf, all from a runnable companion repo.

Java Regex Tutorial: Pattern, Matcher, Groups, Lookarounds and ReDoS

A beginner-first guide to java.util.regex: Pattern and Matcher, named groups, flags, lookarounds and replaceAll with a lambda, then the failure mode. Measured on JDK 25: which patterns still blow up exponentially, what the JDK already defuses, and fixes that work (rewriting, possessive quantifiers, atomic groups, a CharSequence timeout, input limits).

Top 40 Java Concurrency Interview Questions and Answers (2026)

40 Java concurrency interview questions, from race conditions to ScopedValue's exact child-thread inheritance rules. The four trickiest get fresh, verified code and real captured output; the rest link to this site's own deep dives that already proved their claims.

CountDownLatch vs CyclicBarrier vs Phaser vs Semaphore in Java

CountDownLatch, CyclicBarrier, and Phaser implement the same three-round pipeline three ways - reuse semantics, dynamic registration, and a timeout that permanently breaks one of them but not the others. Semaphore solves a genuinely different problem.