Junglewise Threat Intelligence

CVE-2026-83280: Oracle Helidon denial of service in HTTP/2

CVE-2026-83280 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build microservices and web applications. An unauthenticated attacker on the network can exploit a flaw in the HTTP/2 component to crash or hang the application, causing a denial of service. This impacts the availability of services built with affected Helidon versions.

Technical details

A denial-of-service vulnerability exists in the helidon-webserver-http2 component of Oracle Helidon versions 4.0.0 through 4.5.4. The vulnerability is exploitable over the network via HTTP/2 without requiring authentication or user interaction. An attacker can craft a malicious HTTP/2 request that causes the Helidon web server to hang or crash repeatedly, resulting in complete unavailability of services relying on the affected component. The root cause appears related to HTTP/2 protocol handling, though specific details are not fully disclosed. A patch is expected from Oracle.

Affected products

  • Oracle Helidon 4.0.0 through 4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats