Executive brief
Helidon is a web server framework used to build microservices and cloud-native applications within Oracle Fusion Middleware. An unauthenticated attacker on the network can trigger a crash or hang in Helidon, causing the application to become unavailable and disrupting business operations.
Technical details
This is a denial-of-service vulnerability in the Imperative Web Server component of Helidon. An unauthenticated attacker with network access can send specially crafted HTTP requests to cause the server to hang or crash, resulting in complete service unavailability. The vulnerability requires no authentication, user interaction, or special preconditions beyond network access to the affected server. Affected versions are Helidon 3.0.0 through 3.2.18; users should update to a patched release.
Affected products
- Oracle Helidon 3.0.0–3.2.18
Timeline
- 2026-08-18: disclosed