Junglewise Threat Intelligence

CVE-2026-73882: Oracle Helidon denial of service in Imperative Web Server

CVE-2026-73882 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a web server framework used to build microservices and cloud-native applications within Oracle Fusion Middleware. An unauthenticated attacker on the network can trigger a crash or hang in Helidon, causing the application to become unavailable and disrupting business operations.

Technical details

This is a denial-of-service vulnerability in the Imperative Web Server component of Helidon. An unauthenticated attacker with network access can send specially crafted HTTP requests to cause the server to hang or crash, resulting in complete service unavailability. The vulnerability requires no authentication, user interaction, or special preconditions beyond network access to the affected server. Affected versions are Helidon 3.0.0 through 3.2.18; users should update to a patched release.

Affected products

  • Oracle Helidon 3.0.0–3.2.18

Timeline

  • 2026-08-18: disclosed

References

Related threats