Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon 4.0.0‑4.4.1 contains an unauthenticated flaw in its Imperative Web Server component that allows an attacker with network access via HTTP/2 to force the server to hang or crash, causing a complete denial of service. The same attack vector also grants the attacker read access to a limited subset of data that the Helidon instance exposes. The weakness corresponds to improper control of authorization and information exposure, classified as CWE‑284. This dual impact of full availability loss and low confidentiality loss is reflected in the CVSS 3.1 base score of 8.2.

Affected Systems

The affected product is Oracle Helidon 4.0.0 through 4.4.1, a runtime component of Oracle Fusion Middleware. Deployments that expose the HTTP/2 interface to external clients – for example, public‑facing services or reverse‑proxy gateways – are vulnerable. No other versions are known to be affected.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability. The EPSS score of less than 1 % shows a very low but non‑zero likelihood of exploitation, yet the simplicity of sending crafted HTTP/2 requests over a network makes the risk substantial for exposed services. The vulnerability is not listed in CISA’s KEV catalog, suggesting no large‑scale active exploitation yet. Nevertheless, because no authentication is required, any network‑connected client capable of speaking HTTP/2 could trigger the crash or limited data exposure, placing a high priority on remediation.

Generated by OpenCVE AI on August 28, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Helidon patch or upgrade to a version that contains the fix for this vulnerability
  • If an immediate patch is unavailable, block or restrict HTTP/2 traffic to the Helidon server using network firewall rules, reverse‑proxy settings, or application configuration
  • Enforce proper authentication and authorization checks on all Helidon endpoints to ensure only permitted traffic can access the server

Generated by OpenCVE AI on August 28, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Vulnerability in Oracle Helidon 4.5.0 Enables Remote DoS and Data Exposure

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Vulnerability in Oracle Helidon 4.5.0 Enables Remote DoS and Data Exposure

Thu, 20 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Exploit Grants DoS and Data Exposure in Helidon 4.5.0

Wed, 19 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Exploit Grants DoS and Data Exposure in Helidon 4.5.0

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:30:02.571Z

Reserved: 2026-08-13T18:41:45.891Z

Link: CVE-2026-73937

cve-icon Vulnrichment

Updated: 2026-08-19T13:59:30.484Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:26.800

Modified: 2026-08-28T05:16:45.843

Link: CVE-2026-73937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:15:06Z

Weaknesses