Impact
A vulnerability in the Helidon Imperative Web Server grants unauthenticated attackers the ability to send specially crafted HTTP/2 requests that bypass authentication, allowing read access to any data the Helidon instance serves. The flaw does not support modification or denial of service; its impact is limited to the confidentiality of exposed data, aligning with the CVSS 3.1 score of 7.5 and a Confidentiality impact. Versions 4.0.0 through 4.4.1 are affected for Oracle Helidon.
Affected Systems
Oracle Helidon products from version 4.0.0 to 4.4.1 are impacted; no other versions are listed in the CNA data.
Risk and Exploitability
The CVSS score signals high severity, yet the EPSS score of < 1 % indicates a very low probability of exploitation at present. The attack vector remains remote via HTTP/2, and the vulnerability is not yet cataloged in the CISA KEV list. Because the flaw is remote and unauthenticated, a network attacker capable of reaching the Helidon instance can exploit it, but real‑world exploitation will require an attacker to be able to craft and send malicious HTTP/2 traffic to the target.
OpenCVE Enrichment