Executive brief
Helidon is a lightweight framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can exploit a vulnerability in the WebSocket component to temporarily disrupt service availability, affecting the responsiveness and reliability of applications built on this framework.
Technical details
The vulnerability exists in the WebSocket component of Oracle Helidon versions 4.0.0 through 4.5.4. It is an easily exploitable flaw that allows an unauthenticated attacker with network access to send crafted HTTP requests that trigger a partial denial of service condition. The attack requires no authentication, user interaction, or special configuration, and can be launched remotely over the network. Successful exploitation results in partial unavailability of the affected Helidon instance. Oracle has issued a security update addressing this issue.
Affected products
- Oracle Helidon 4.0.0-4.5.4
Timeline
- 2026-09-15: disclosed
- 2026-09-15: advisory