Junglewise Threat Intelligence

CVE-2026-83330: Oracle Helidon WebSocket denial of service

CVE-2026-83330 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight Java framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can send crafted HTTP requests to the WebSocket component, causing the application to hang or crash repeatedly, resulting in a complete denial of service. No user authentication or interaction is required to exploit this vulnerability.

Technical details

This is a denial-of-service vulnerability in the WebSocket component of Oracle Helidon (versions 4.0.0 through 4.5.4). The vulnerability is easily exploitable and requires only network access via HTTP; no authentication or user interaction is needed. An attacker can craft malicious HTTP requests to trigger a hang or repeated crash of the affected Helidon instance, causing complete unavailability. The vulnerability has a CVSS 3.1 score of 7.5 with High severity, impacting only availability. Patch availability and specific technical root cause details were not accessible in the provided advisory.

Affected products

  • Oracle Helidon 4.0.0 through 4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats