Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via HTTP/2 crash
Action: Immediate Patch
AI Analysis

Impact

A flaw in Oracle Helidon’s HTTP/2 web client component allows an unauthenticated attacker to send crafted HTTP/2 requests that force the Helidon server to hang or crash repeatedly, leading to a complete denial of service. The weakness is an uncontrolled resource exhaustion that will expose the Helidon service to prolonged outages, impacting availability without compromising confidentiality or integrity.

Affected Systems

Oracle’s Helidon product, versions 4.0.0 through 4.5.4, is affected. All Helidon deployments that support HTTP/2 over unprotected network interfaces are vulnerable, regardless of the specific Helidon variant or application built on it.

Risk and Exploitability

The CVSS v3.1 score of 7.5 classifies the vulnerability as high severity, reflecting the availability impact. The EPSS score remains below 1%, indicating that public exploitation has not yet been observed, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the requirement for only network access via HTTP/2 and no authentication makes the attack straightforward for an attacker who can reach the service, underscoring the importance of remediation even if exploit prevalence is low.

Generated by OpenCVE AI on September 18, 2026 at 18:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle Helidon to version 4.5.5 or later to remove the HTTP/2 crash flaw
  • If upgrading is not feasible, disable HTTP/2 support or bind the Helidon service to a tightly controlled network segment
  • Apply network segmentation or firewall rules to restrict access to the Helidon host and mitigate potential remote denial‑of‑service attempts

Generated by OpenCVE AI on September 18, 2026 at 18:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Helidon WebClient HTTP/2 Denial of Service Vulnerability

Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Helidon WebClient HTTP/2 Denial of Service Vulnerability

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:53.730Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83276

cve-icon Vulnrichment

Updated: 2026-09-15T23:13:08.388Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:40.000

Modified: 2026-09-28T15:14:38.140

Link: CVE-2026-83276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:45:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption