Impact
Helidon 3.2.17 and earlier contains a vulnerability in its Imperative Web Server that allows an unauthenticated attacker to send HTTP requests that trigger a partial denial‑of‑service. According to the CVSS vector, the flaw impacts only availability; confidentiality and integrity remain unaffected.
Affected Systems
Oracle Corporation’s Helidon middleware, versions 3.0.0-3.2.17, is affected. The vulnerability lies in the Imperative Web Server component of these releases; no other listed Helidon or Oracle product versions are currently reported as impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects a medium risk; the EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is via network access to the HTTP port; no authentication or elevated privileges are required. An attacker can launch the request from any machine that can reach the Helidon service, potentially causing a short‑lived service interruption until the server recovers or a patch is applied.
OpenCVE Enrichment