Impact
Oracle Helidon versions 3.0.0 through 3.2.17’s Imperative Web Server contains an easily exploitable flaw (CWE‑400: Uncontrolled Resource Consumption) that allows an unauthenticated attacker with network access via HTTP to trigger a hang or repeated crash. The impact is a complete denial of availability; the flaw does not provide confidentiality or integrity compromise. It is classified as a high availability impact with a CVSS score of 7.5 and an attack vector of network, accessible without authentication or user interaction.
Affected Systems
Oracle Helidon products, versions 3.0.0 through 3.2.17, are affected by this vulnerability.
Risk and Exploitability
With the CVSS score of 7.5 the vulnerability is of moderate‑to‑high severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The lack of authentication and simple HTTP trigger make the vulnerability prone to exploitation, allowing an attacker to trigger a denial‑of‑service from any network‑reachable device without privileged access.
OpenCVE Enrichment