Executive brief
Helidon is an open-source Java framework used to build microservices and cloud-native applications. This critical vulnerability in the Imperative Web Server component allows an unauthenticated attacker to gain complete control over the affected service via a network request, potentially compromising sensitive data, disrupting operations, and enabling further attacks on connected systems.
Technical details
This vulnerability in Oracle Helidon's Imperative Web Server component affects versions 3.0.0 through 3.2.17. The vulnerability is easily exploitable and requires no authentication or user interaction—an attacker with network access can craft a malicious HTTP request to trigger the flaw. Successful exploitation results in complete takeover (remote code execution) of the Helidon service. The attack vector is network-based and requires only HTTP access to the affected web server. CVSS v3.1 score is 9.8 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting critical impact to confidentiality, integrity, and availability. Patches are available from Oracle as of the publication date.
Affected products
- Oracle Helidon 3.0.0-3.2.17
Timeline
- 2026-08-18: disclosed