Junglewise Threat Intelligence

CVE-2026-87289: Oracle Helidon webserver static content denial of service

CVE-2026-87289 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is an open-source microservices framework used to build lightweight Java applications. A denial-of-service vulnerability in its static content serving component allows unauthenticated attackers to remotely crash or hang the Helidon server via HTTP requests, disrupting application availability without requiring authentication or user interaction.

Technical details

This vulnerability exists in the helidon-webserver-static-content component of Helidon versions 4.0.0 through 4.5.4. The flaw is easily exploitable and allows an unauthenticated attacker with network access to send crafted HTTP requests that cause a hang or repeated crash of the affected server, resulting in denial of service. The attack requires no privileges, no special configuration, and no user interaction. The vulnerability impacts only availability; there is no impact to confidentiality or integrity. Patches are expected to be available from Oracle.

Affected products

  • Oracle Helidon 4.0.0 to 4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats