Executive brief
Helidon is a lightweight web server component used within Oracle Fusion Middleware to handle HTTP requests. An unauthenticated attacker can exploit a flaw in HTTP/2 handling to crash the server or cause it to hang, resulting in complete service unavailability for applications relying on it. No authentication or user interaction is required.
Technical details
The vulnerability is a denial-of-service condition in the Helidon Imperative Web Server component (versions 4.0.0 through 4.4.1) triggered via malformed or specially crafted HTTP/2 requests. The flaw is easily exploitable over the network without authentication, allowing an attacker to send crafted HTTP/2 traffic that causes the server to hang or crash. The attack has no impact on confidentiality or integrity, only availability. A patch is expected from Oracle as part of their security update process.
Affected products
- Oracle Helidon 4.0.0 through 4.4.1
Timeline
- 2026-08-18: disclosed