Executive brief
Oracle Helidon is a lightweight Java framework used to build microservices and web applications. A vulnerability in its Imperative Web Server component allows unauthenticated attackers to read sensitive data through HTTP requests without proper authorization, potentially exposing configuration, credentials, or application data.
Technical details
The vulnerability is an information disclosure flaw in the Helidon Imperative Web Server component affecting versions 4.0.0 through 4.4.1. The issue allows unauthenticated attackers with network access to make HTTP requests that bypass access controls and retrieve restricted data. The attack requires no authentication, user interaction, or special conditions—any network-reachable instance is vulnerable. Successful exploitation results in unauthorized read access to sensitive Helidon data, though integrity and availability are not affected.
Affected products
- Oracle Helidon 4.0.0 through 4.4.1
Timeline
- 2026-08-18: disclosed