Junglewise Threat Intelligence

CVE-2026-83480: Oracle Helidon WebSocket denial of service

CVE-2026-83480 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can exploit a vulnerability in the WebSocket component to temporarily disrupt service availability, affecting the responsiveness and reliability of applications built on this framework.

Technical details

The vulnerability exists in the WebSocket component of Oracle Helidon versions 4.0.0 through 4.5.4. It is an easily exploitable flaw that allows an unauthenticated attacker with network access to send crafted HTTP requests that trigger a partial denial of service condition. The attack requires no authentication, user interaction, or special configuration, and can be launched remotely over the network. Successful exploitation results in partial unavailability of the affected Helidon instance. Oracle has issued a security update addressing this issue.

Affected products

  • Oracle Helidon 4.0.0-4.5.4

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats