Impact
A flaw in Oracle Helidon’s HTTP/2 web client component allows an unauthenticated attacker to send crafted HTTP/2 requests that force the Helidon server to hang or crash repeatedly, leading to a complete denial of service. The weakness is an uncontrolled resource exhaustion that will expose the Helidon service to prolonged outages, impacting availability without compromising confidentiality or integrity.
Affected Systems
Oracle’s Helidon product, versions 4.0.0 through 4.5.4, is affected. All Helidon deployments that support HTTP/2 over unprotected network interfaces are vulnerable, regardless of the specific Helidon variant or application built on it.
Risk and Exploitability
The CVSS v3.1 score of 7.5 classifies the vulnerability as high severity, reflecting the availability impact. The EPSS score remains below 1%, indicating that public exploitation has not yet been observed, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the requirement for only network access via HTTP/2 and no authentication makes the attack straightforward for an attacker who can reach the service, underscoring the importance of remediation even if exploit prevalence is low.
OpenCVE Enrichment