Executive brief
Oracle Helidon is a lightweight web application framework used to build microservices and cloud-native applications. An attacker can remotely crash or hang Helidon web servers without authentication, causing complete service outages for any applications built on the affected framework versions. This enables attackers to disrupt business operations and customer access to web services.
Technical details
This is a denial-of-service vulnerability in the Imperative Web Server component of Helidon versions 1.0.0 through 1.4.19. The vulnerability is easily exploitable and requires no authentication; it can be triggered by any unauthenticated attacker with network access via HTTP. Successful exploitation causes Helidon to hang or crash repeatedly, resulting in complete unavailability of services running on affected versions. The vulnerability has a CVSS v3.1 base score of 7.5 with impacts limited to availability. A patch is expected to be available via Oracle's security updates.
Affected products
- Oracle Helidon 1.0.0 through 1.4.19
Timeline
- 2026-08-18: disclosed