Executive brief
Oracle Helidon is a lightweight Java framework used to build microservices and web applications. An unauthenticated attacker can exploit a flaw in the HTTP/2 implementation to gain unauthorized access to sensitive data stored within or accessible to the application, without requiring any authentication or user interaction.
Technical details
This vulnerability in the Helidon Imperative Web Server component affects versions 4.0.0 through 4.4.1. The flaw allows an unauthenticated attacker with network access to send specially crafted HTTP/2 requests that bypass authentication controls, resulting in unauthorized data access. The attack is easily exploitable, requires no user interaction, and can lead to complete disclosure of sensitive data accessible to the Helidon instance. Patches are expected to be available through Oracle's security update channels.
Affected products
- Oracle Helidon 4.0.0-4.4.1
Timeline
- 2026-08-18: disclosed