Executive brief
Oracle Helidon is a web server framework used to build microservices and cloud-native applications in the Java ecosystem. An unauthenticated network attacker can exploit this vulnerability to cause a partial denial of service, disrupting availability of services built on affected Helidon versions without requiring any authentication or user interaction.
Technical details
This vulnerability in Oracle Helidon's Imperative Web Server component allows an unauthenticated attacker with network access to trigger a partial denial of service via HTTP requests. The vulnerability is easily exploitable (low complexity, no privileges required) and requires only network reachability to the Helidon service. A successful attack results in partial unavailability of the affected Helidon instance. The vulnerability affects Helidon versions 3.0.0 through 3.2.17, and a patch is likely available through Oracle's security updates.
Affected products
- Oracle Helidon 3.0.0 through 3.2.17
Timeline
- 2026-08-18: disclosed