Executive brief
Oracle Helidon is a lightweight Java web server framework used to build microservices and cloud-native applications. An unauthenticated attacker can exploit this vulnerability over the network using HTTP/2 to read sensitive data from the web server and temporarily disrupt its availability, potentially affecting business operations that depend on Helidon-based services.
Technical details
This vulnerability in the Helidon Imperative Web Server allows unauthenticated attackers to exploit an issue via HTTP/2 protocol handling. The vulnerability requires no authentication and no user interaction, making it easily exploitable for any attacker with network access. Successful exploitation results in unauthorized read access to a subset of Helidon-accessible data and the ability to cause partial denial of service. The affected versions are 4.0.0 through 4.4.1; patches should be available in newer releases.
Affected products
- Oracle Helidon 4.0.0-4.4.1
Timeline
- 2026-08-18: disclosed