Impact
Oracle Helidon versions 3.0.0 through 3.2.18 contain a vulnerability that allows an unauthenticated attacker with network access via HTTP to cause the Imperative Web Server to hang or repeatedly crash, resulting in a loss of availability for the Helidon instance. The flaw permits a denial‑of‑service attack without requiring authentication or privileged access, and it carries a CVSS v3.1 Base Score of 7.5.
Affected Systems
The affected product is Oracle Helidon versions 3.0.0 through 3.2.18. No other products are listed as impacted.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability exposes an unprotected HTTP endpoint that can be accessed from outside the network; attackers do not require credentials or special privileges and simply need network connectivity to the Helidon service. With a high impact on availability, the CVSS score of 7.5 reflects the severity. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability, and the issue is not listed in CISA's KEV catalog. If exploited, the attack would cause a permanent or repeatable denial of service, disrupting any applications relying on Helidon.
OpenCVE Enrichment