Junglewise Threat Intelligence

CVE-2026-73896: Oracle Helidon information disclosure and denial of service via HTTP/2

CVE-2026-73896 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java web server framework used to build microservices and cloud-native applications. An unauthenticated attacker can exploit this vulnerability over the network using HTTP/2 to read sensitive data from the web server and temporarily disrupt its availability, potentially affecting business operations that depend on Helidon-based services.

Technical details

This vulnerability in the Helidon Imperative Web Server allows unauthenticated attackers to exploit an issue via HTTP/2 protocol handling. The vulnerability requires no authentication and no user interaction, making it easily exploitable for any attacker with network access. Successful exploitation results in unauthorized read access to a subset of Helidon-accessible data and the ability to cause partial denial of service. The affected versions are 4.0.0 through 4.4.1; patches should be available in newer releases.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats