Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon versions 3.0.0 through 3.2.17’s Imperative Web Server contains an easily exploitable flaw (CWE‑400: Uncontrolled Resource Consumption) that allows an unauthenticated attacker with network access via HTTP to trigger a hang or repeated crash. The impact is a complete denial of availability; the flaw does not provide confidentiality or integrity compromise. It is classified as a high availability impact with a CVSS score of 7.5 and an attack vector of network, accessible without authentication or user interaction.

Affected Systems

Oracle Helidon products, versions 3.0.0 through 3.2.17, are affected by this vulnerability.

Risk and Exploitability

With the CVSS score of 7.5 the vulnerability is of moderate‑to‑high severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The lack of authentication and simple HTTP trigger make the vulnerability prone to exploitation, allowing an attacker to trigger a denial‑of‑service from any network‑reachable device without privileged access.

Generated by OpenCVE AI on August 28, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for vendor updates and apply any available fixes to Helidon 3.2.18 or later releases
  • If no updates are available, restrict the Helidon service to trusted IP addresses or place it behind a firewall or VPN to block unauthenticated network access
  • Configure the service to restart automatically and monitor logs for repeated crashes to detect denial‑of‑service activity

Generated by OpenCVE AI on August 28, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.18 Denial‑of‑Service via HTTP

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Sat, 22 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.18 Denial‑of‑Service via HTTP

Sat, 22 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.18 Denial of Service via Unauthenticated HTTP Crash
Weaknesses CWE-770

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.18 Denial of Service via Unauthenticated HTTP Crash
Weaknesses CWE-770

Fri, 21 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Denial of Service in Oracle Helidon 3.2.18
Weaknesses CWE-400

Wed, 19 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Denial of Service in Oracle Helidon 3.2.18
Weaknesses CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:33:24.217Z

Reserved: 2026-08-04T22:06:34.605Z

Link: CVE-2026-70908

cve-icon Vulnrichment

Updated: 2026-08-22T02:15:54.670Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:48.633

Modified: 2026-08-28T05:16:43.310

Link: CVE-2026-70908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:00:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption