Executive brief
Oracle Helidon is a lightweight Java framework used to build microservices. A vulnerability in its JSON processing component allows an unauthenticated attacker to send specially crafted HTTP requests that cause a partial service outage without requiring any authentication or special access. This could impact the availability of applications relying on Helidon for critical business functions.
Technical details
This is a denial-of-service vulnerability in the JSON parsing component of Oracle Helidon framework versions 4.0.0 through 4.5.4. The vulnerability is easily exploitable, requiring no authentication and accessible via the network through HTTP. An unauthenticated attacker can craft malicious JSON payloads that trigger excessive resource consumption, resulting in partial denial of service of the affected Helidon instance. The attack vector is network-based with low complexity and no user interaction required. Patches are expected in Oracle's regular security update cycle.
Affected products
- Oracle Helidon 4.0.0-4.5.4
Timeline
- 2026-09-15: disclosed