Junglewise Threat Intelligence

CVE-2026-73871: Oracle Helidon information disclosure via HTTP

CVE-2026-73871 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight, cloud-native web server framework used to build microservices and web applications. A vulnerability in Helidon allows unauthenticated attackers to access sensitive data over the network without requiring credentials or special interaction. Successful exploitation could expose confidential application data to unauthorized parties.

Technical details

This is an information disclosure vulnerability in Oracle Helidon's Imperative Web Server component affecting versions 3.0.0 through 3.2.17. The vulnerability is easily exploitable via an unauthenticated HTTP network request, requiring no user interaction or authentication. An attacker can read a subset of data accessible to Helidon, resulting in unauthorized information disclosure without impact to data integrity or availability. A patch is presumed available; users should update to version 3.2.18 or later.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats