Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon product of Oracle Fusion Middleware contains a flaw in the Imperative Web Server. Versions 4.0.0 through 4.5.2 are affected. An unauthenticated attacker with network access via HTTP can exploit the vulnerability to cause a partial denial of service. The vulnerability is an access control weakness classified as CWE-284, allowing requests to overload or destabilize the server without compromising confidentiality or integrity.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.5.2 are affected by this vulnerability. The flaw resides in the Imperative Web Server component and can be triggered by any HTTP request. No other Oracle Fusion Middleware products or components are listed as impacted.

Risk and Exploitability

The CVSS Base Score of 5.3 indicates moderate risk for availability. The EPSS score is under 1 % and the vulnerability is not listed in the CISA KEV catalog, signifying a low probability of widespread exploitation. The likely attack vector is network‑based HTTP traffic; an unauthenticated attacker with network access can trigger this DoS by sending malicious requests over a standard web port.

Generated by OpenCVE AI on August 28, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a patch or upgrade to a Helidon release that has fixed the access‑control flaw.
  • Configure firewalls or a reverse proxy to allow only trusted networks or IP addresses to reach the Helidon HTTP endpoint.
  • Enable request throttling or rate limiting within Helidon to mitigate bursts of malformed or excessive requests.
  • Monitor Helidon logs and performance metrics for sudden spikes or error patterns and investigate anomalies promptly.

Generated by OpenCVE AI on August 28, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Partial Denial of Service in Oracle Helidon 4.5.3

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Partial Denial of Service in Oracle Helidon 4.5.3

Thu, 20 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Partial Denial of Service in Oracle Helidon 4.5.3

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Partial Denial of Service in Oracle Helidon 4.5.3

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Vulnerability Enables Unauthenticated Denial of Service via HTTP
Weaknesses CWE-20

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Vulnerability Enables Unauthenticated Denial of Service via HTTP
Weaknesses CWE-20

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:33:09.478Z

Reserved: 2026-08-13T18:41:45.891Z

Link: CVE-2026-73932

cve-icon Vulnrichment

Updated: 2026-08-19T12:07:52.511Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:26.227

Modified: 2026-08-28T20:19:51.587

Link: CVE-2026-73932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:45:05Z

Weaknesses