Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Helidon 3.2.17 and earlier contains a vulnerability in its Imperative Web Server that allows an unauthenticated attacker to send HTTP requests that trigger a partial denial‑of‑service. According to the CVSS vector, the flaw impacts only availability; confidentiality and integrity remain unaffected.

Affected Systems

Oracle Corporation’s Helidon middleware, versions 3.0.0-3.2.17, is affected. The vulnerability lies in the Imperative Web Server component of these releases; no other listed Helidon or Oracle product versions are currently reported as impacted.

Risk and Exploitability

The CVSS score of 5.3 reflects a medium risk; the EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is via network access to the HTTP port; no authentication or elevated privileges are required. An attacker can launch the request from any machine that can reach the Helidon service, potentially causing a short‑lived service interruption until the server recovers or a patch is applied.

Generated by OpenCVE AI on August 28, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether an Oracle patch or update addressing the Helidon 3.2.18 vulnerability is available; apply if found.
  • Restrict HTTP access to Helidon by limiting connections to trusted IP addresses or hosts, or place the service behind a firewall or load balancer to block unauthenticated traffic.
  • Monitor Helidon logs and network traffic for repeated or anomalous requests that could indicate a DoS attempt, and set up alerts for high request rates.

Generated by OpenCVE AI on August 28, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.18 Partial Denial of Service via HTTP

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.18 Partial Denial of Service via HTTP

Thu, 20 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP DoS Vulnerability in Oracle Helidon 3.2.18

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP DoS Vulnerability in Oracle Helidon 3.2.18

Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leading to Partial Denial of Service in Oracle Helidon 3.2.18
Weaknesses CWE-400

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leading to Partial Denial of Service in Oracle Helidon 3.2.18
Weaknesses CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:17:38.216Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71161

cve-icon Vulnrichment

Updated: 2026-08-19T12:08:31.628Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:17.443

Modified: 2026-08-28T20:19:43.990

Link: CVE-2026-71161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses