Impact
Oracle Helidon’s helidon-webserver-http2 component (versions 4.0.0 through 4.5.4) contains an uncontrolled resource consumption flaw. An unauthenticated attacker who can open an HTTP/2 connection to the server can force Helidon to hang or crash repeatedly, exhausting availability. The CVSS 3.1 score of 7.5 reflects a high impact on availability with no denial of user experience or system integrity.
Affected Systems
Helidon, a product of Oracle Corporation, is affected in all released minor versions from 4.0.0 to 4.5.4. No specific patch versions are listed, indicating that all builds within this range remain vulnerable.
Risk and Exploitability
The vulnerability is network‑based and requires no authentication, making it highly accessible from any host that can reach the Helidon service. Despite the difficulty being low and the EPSS score being below 1%, no public exploitation data exists and the vulnerability is not catalogued in CISA KEV. Nonetheless, attackers can effect a complete denial of service by sending crafted HTTP/2 requests, making this a significant availability risk for exposed services.
OpenCVE Enrichment