Executive brief
Helidon is a lightweight Java framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can send specially crafted requests to cause the Helidon web server to hang or crash, resulting in a complete service outage with no warning signs or authentication barriers.
Technical details
This is a denial-of-service vulnerability in the Helidon webserver component affecting versions 4.0.0 through 4.5.4. The vulnerability is easily exploitable without authentication and requires only network access via TCP to trigger. An attacker can craft malicious requests that cause the server to hang or crash repeatedly, completely disrupting service availability. The attack has no preconditions beyond network connectivity and does not require user interaction or authentication.
Affected products
- Oracle Helidon 4.0.0-4.5.4
Timeline
- 2026-09-15: disclosed