Junglewise Threat Intelligence

CVE-2026-83458: Oracle Helidon denial of service in JSON parsing

CVE-2026-83458 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build microservices. A vulnerability in its JSON processing component allows an unauthenticated attacker to send specially crafted HTTP requests that cause a partial service outage without requiring any authentication or special access. This could impact the availability of applications relying on Helidon for critical business functions.

Technical details

This is a denial-of-service vulnerability in the JSON parsing component of Oracle Helidon framework versions 4.0.0 through 4.5.4. The vulnerability is easily exploitable, requiring no authentication and accessible via the network through HTTP. An unauthenticated attacker can craft malicious JSON payloads that trigger excessive resource consumption, resulting in partial denial of service of the affected Helidon instance. The attack vector is network-based with low complexity and no user interaction required. Patches are expected in Oracle's regular security update cycle.

Affected products

  • Oracle Helidon 4.0.0-4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats