Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon Imperative Web Server component (versions 4.0.0‑4.4.1) contains a CWE‑284: Access Control flaw in its handling of HTTP/2 requests; an unauthenticated attacker can send crafted traffic that forces the service to hang or repeatedly crash, resulting in a loss of availability. The vulnerability does not expose data or grant control over system configurations, so confidentiality and integrity remain intact.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.4.1 are affected. The vulnerability is present in the Helidon Imperative Web Server component of these releases. No other product families or versions are listed as affected in the CNA data.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 classifies the attack as high risk to availability. The EPSS score is <1 %, indicating a low probability of exploitation in the wild, and the issue is not present in CISA’s KEV catalog. An attacker requires network access to a Helidon deployment over HTTP/2; no prior authentication or privileged credentials are needed for the denial‑of‑service effect.

Generated by OpenCVE AI on August 29, 2026 at 00:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Helidon to version 4.5.0 or later once the vendor releases an official patch.
  • If an upgrade cannot be performed immediately, block or restrict HTTP/2 traffic to the Helidon server, or enable access controls that limit connections to trusted networks or authenticated users.
  • Add runtime monitoring to detect repeated crashes or hangs and configure the system to automatically restart the Helidon service or trigger alert notifications for manual intervention.

Generated by OpenCVE AI on August 29, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted HTTP/2 Requests in Oracle Helidon

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Remote DoS via Helidon Imperative Web Server

Fri, 21 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Remote DoS via Helidon Imperative Web Server
Weaknesses CWE-1017
CWE-285

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Denial of Service in Oracle Helidon 4.5.0

Wed, 19 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Denial of Service in Oracle Helidon 4.5.0
Weaknesses CWE-1017
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:22:17.439Z

Reserved: 2026-08-13T18:41:45.884Z

Link: CVE-2026-73890

cve-icon Vulnrichment

Updated: 2026-08-20T18:11:21.413Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:21.533

Modified: 2026-08-28T20:19:47.757

Link: CVE-2026-73890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses