Junglewise Threat Intelligence

CVE-2026-70908: Oracle Helidon denial-of-service via HTTP

CVE-2026-70908 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight Java framework used to build cloud-native web applications and microservices. An unauthenticated remote attacker can crash or hang the Helidon server by sending specially crafted HTTP requests, causing complete service outages without requiring authentication or user interaction.

Technical details

The vulnerability in Helidon's Imperative Web Server component allows an unauthenticated attacker to trigger a denial-of-service condition via network-accessible HTTP endpoints. The flaw is easily exploitable and requires no authentication, user interaction, or complex attack setup (CVSS vector indicates low complexity). Successful exploitation causes the Helidon process to hang or crash repeatedly, resulting in complete unavailability of affected services. Affected versions are Helidon 3.0.0 through 3.2.17; patches and mitigations should be available from Oracle.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats