Junglewise Threat Intelligence

CVE-2026-71161: Oracle Helidon denial of service vulnerability in Imperative Web Server

CVE-2026-71161 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a web server framework used to build microservices and cloud-native applications in the Java ecosystem. An unauthenticated network attacker can exploit this vulnerability to cause a partial denial of service, disrupting availability of services built on affected Helidon versions without requiring any authentication or user interaction.

Technical details

This vulnerability in Oracle Helidon's Imperative Web Server component allows an unauthenticated attacker with network access to trigger a partial denial of service via HTTP requests. The vulnerability is easily exploitable (low complexity, no privileges required) and requires only network reachability to the Helidon service. A successful attack results in partial unavailability of the affected Helidon instance. The vulnerability affects Helidon versions 3.0.0 through 3.2.17, and a patch is likely available through Oracle's security updates.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats