Impact
Helidon’s Imperative Web Server component contains a flaw that permits an unauthenticated attacker with network access via HTTP/2 to send crafted traffic, causing the server to hang or repeatedly crash. Successful attacks can result in an unauthorized ability to cause a hang or repeatable crash (complete Denial of Service) of Helidon. Supported versions 4.0.0 through 4.5.0 are affected. The weakness is reflected in the CVSS 3.1 score of 7.5, indicating a strong availability compromise with low complexity and no prerequisite. CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.0 are affected. The flaw exists in the Helidon Imperative Web Server component of Oracle Fusion Middleware. No other product versions are listed.
Risk and Exploitability
The CVSS base score of 7.5 highlights a significant availability impact, while the EPSS score of < 1% indicates that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog, but because it is easily exploitable and requires only network access via HTTP/2, the potential for disruptive attacks in environments that expose Helidon to the internet remains high. An unauthenticated attacker can trigger the denial of service by establishing an HTTP/2 connection.
OpenCVE Enrichment