Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Availability)
Action: Apply Patch
AI Analysis

Impact

Oracle Helidon’s helidon-webserver-http2 component (versions 4.0.0 through 4.5.4) contains an uncontrolled resource consumption flaw. An unauthenticated attacker who can open an HTTP/2 connection to the server can force Helidon to hang or crash repeatedly, exhausting availability. The CVSS 3.1 score of 7.5 reflects a high impact on availability with no denial of user experience or system integrity.

Affected Systems

Helidon, a product of Oracle Corporation, is affected in all released minor versions from 4.0.0 to 4.5.4. No specific patch versions are listed, indicating that all builds within this range remain vulnerable.

Risk and Exploitability

The vulnerability is network‑based and requires no authentication, making it highly accessible from any host that can reach the Helidon service. Despite the difficulty being low and the EPSS score being below 1%, no public exploitation data exists and the vulnerability is not catalogued in CISA KEV. Nonetheless, attackers can effect a complete denial of service by sending crafted HTTP/2 requests, making this a significant availability risk for exposed services.

Generated by OpenCVE AI on September 18, 2026 at 19:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor patch or update that addresses the issue.
  • If an upgrade is not immediately possible, block or restrict HTTP/2 traffic on the server to trusted internal networks or high‑trust hosts.
  • If the software offers a configuration option, disable HTTP/2 support entirely until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Helidon HTTP/2 Denial of Service via Unauthenticated Request

Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Helidon HTTP/2 Denial of Service via Unauthenticated Request

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:53.586Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83280

cve-icon Vulnrichment

Updated: 2026-09-15T23:13:05.047Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:40.593

Modified: 2026-09-28T15:14:44.383

Link: CVE-2026-83280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:15:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption