Junglewise Threat Intelligence

CVE-2026-71153: Oracle Helidon denial of service vulnerability in Imperative Web Server

CVE-2026-71153 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight web application framework used to build microservices and cloud-native applications. An attacker can remotely crash or hang Helidon web servers without authentication, causing complete service outages for any applications built on the affected framework versions. This enables attackers to disrupt business operations and customer access to web services.

Technical details

This is a denial-of-service vulnerability in the Imperative Web Server component of Helidon versions 1.0.0 through 1.4.19. The vulnerability is easily exploitable and requires no authentication; it can be triggered by any unauthenticated attacker with network access via HTTP. Successful exploitation causes Helidon to hang or crash repeatedly, resulting in complete unavailability of services running on affected versions. The vulnerability has a CVSS v3.1 base score of 7.5 with impacts limited to availability. A patch is expected to be available via Oracle's security updates.

Affected products

  • Oracle Helidon 1.0.0 through 1.4.19

Timeline

  • 2026-08-18: disclosed

References

Related threats