Executive brief
Helidon is a lightweight Java framework used to build cloud-native web applications and microservices. An unauthenticated remote attacker can crash or hang the Helidon server by sending specially crafted HTTP requests, causing complete service outages without requiring authentication or user interaction.
Technical details
The vulnerability in Helidon's Imperative Web Server component allows an unauthenticated attacker to trigger a denial-of-service condition via network-accessible HTTP endpoints. The flaw is easily exploitable and requires no authentication, user interaction, or complex attack setup (CVSS vector indicates low complexity). Successful exploitation causes the Helidon process to hang or crash repeatedly, resulting in complete unavailability of affected services. Affected versions are Helidon 3.0.0 through 3.2.17; patches and mitigations should be available from Oracle.
Affected products
- Oracle Helidon 3.0.0 through 3.2.17
Timeline
- 2026-08-18: disclosed