Executive brief
Helidon is a lightweight Java framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can send crafted HTTP requests to the WebSocket component, causing the application to hang or crash repeatedly, resulting in a complete denial of service. No user authentication or interaction is required to exploit this vulnerability.
Technical details
This is a denial-of-service vulnerability in the WebSocket component of Oracle Helidon (versions 4.0.0 through 4.5.4). The vulnerability is easily exploitable and requires only network access via HTTP; no authentication or user interaction is needed. An attacker can craft malicious HTTP requests to trigger a hang or repeated crash of the affected Helidon instance, causing complete unavailability. The vulnerability has a CVSS 3.1 score of 7.5 with High severity, impacting only availability. Patch availability and specific technical root cause details were not accessible in the provided advisory.
Affected products
- Oracle Helidon 4.0.0 through 4.5.4
Timeline
- 2026-09-15: disclosed