Impact
Oracle Helidon 4.0.0‑4.4.1 contains an unauthenticated flaw in its Imperative Web Server component that allows an attacker with network access via HTTP/2 to force the server to hang or crash, causing a complete denial of service. The same attack vector also grants the attacker read access to a limited subset of data that the Helidon instance exposes. The weakness corresponds to improper control of authorization and information exposure, classified as CWE‑284. This dual impact of full availability loss and low confidentiality loss is reflected in the CVSS 3.1 base score of 8.2.
Affected Systems
The affected product is Oracle Helidon 4.0.0 through 4.4.1, a runtime component of Oracle Fusion Middleware. Deployments that expose the HTTP/2 interface to external clients – for example, public‑facing services or reverse‑proxy gateways – are vulnerable. No other versions are known to be affected.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. The EPSS score of less than 1 % shows a very low but non‑zero likelihood of exploitation, yet the simplicity of sending crafted HTTP/2 requests over a network makes the risk substantial for exposed services. The vulnerability is not listed in CISA’s KEV catalog, suggesting no large‑scale active exploitation yet. Nevertheless, because no authentication is required, any network‑connected client capable of speaking HTTP/2 could trigger the crash or limited data exposure, placing a high priority on remediation.
OpenCVE Enrichment