Executive brief
Oracle Helidon is a lightweight Java framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can exploit an HTTP/2 vulnerability in the web client component to crash or hang the application, causing a complete denial of service. No user interaction or authentication is required to trigger the attack.
Technical details
A denial-of-service vulnerability exists in the helidon-webclient-http2 component of Oracle Helidon versions 4.0.0 through 4.5.4. The vulnerability is easily exploitable and reachable via network access over HTTP/2 without requiring authentication or user interaction. An attacker can craft malicious HTTP/2 requests to trigger a hang or crash in the application, resulting in complete unavailability. The CVSS 3.1 score of 7.5 reflects the high availability impact with no confidentiality or integrity compromise. Patch availability and specific attack mechanics are not detailed in the advisory.
Affected products
- Oracle Helidon 4.0.0 to 4.5.4
Timeline
- 2026-09-15: disclosed