Executive brief
Oracle Helidon is a lightweight Java framework used to build microservices and cloud-native applications. A vulnerability in its multipart media handling component allows unauthenticated attackers to trigger a partial denial of service via network requests, potentially disrupting service availability for legitimate users without requiring authentication or user interaction.
Technical details
The vulnerability exists in the helidon-media-multipart component of Oracle Helidon (versions 3.0.0 through 3.2.20) and is exploitable via HTTP requests from unauthenticated, network-accessible attackers. The flaw is easily exploitable with no authentication or special conditions required (AC:L). A successful attack results in partial denial of service affecting availability of the Helidon application. The vulnerability has a CVSS 3.1 score of 5.3, reflecting low-to-medium impact on availability with no confidentiality or integrity compromise.
Affected products
- Oracle Helidon 3.0.0-3.2.20
Timeline
- 2026-09-15: disclosed