Junglewise Threat Intelligence

CVE-2026-73887: Oracle Helidon data access vulnerability in HTTP/2

CVE-2026-73887 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build microservices and web applications. An unauthenticated attacker can exploit a flaw in the HTTP/2 implementation to gain unauthorized access to sensitive data stored within or accessible to the application, without requiring any authentication or user interaction.

Technical details

This vulnerability in the Helidon Imperative Web Server component affects versions 4.0.0 through 4.4.1. The flaw allows an unauthenticated attacker with network access to send specially crafted HTTP/2 requests that bypass authentication controls, resulting in unauthorized data access. The attack is easily exploitable, requires no user interaction, and can lead to complete disclosure of sensitive data accessible to the Helidon instance. Patches are expected to be available through Oracle's security update channels.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats