Impact
The Helidon Imperative Web Server component (versions 4.0.0‑4.4.1) contains a CWE‑284: Access Control flaw in its handling of HTTP/2 requests; an unauthenticated attacker can send crafted traffic that forces the service to hang or repeatedly crash, resulting in a loss of availability. The vulnerability does not expose data or grant control over system configurations, so confidentiality and integrity remain intact.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. The vulnerability is present in the Helidon Imperative Web Server component of these releases. No other product families or versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 classifies the attack as high risk to availability. The EPSS score is <1 %, indicating a low probability of exploitation in the wild, and the issue is not present in CISA’s KEV catalog. An attacker requires network access to a Helidon deployment over HTTP/2; no prior authentication or privileged credentials are needed for the denial‑of‑service effect.
OpenCVE Enrichment