Impact
Helidon’s web server contains a resource exhaustion flaw that can be triggered by an unauthenticated TCP connection. The bug allows an attacker to make the service hang or crash repeatedly, leading to a full denial of service. The weakness is a classic example of a CWE‑400 input‑sized resource exhaustion vulnerability, with no impact on confidentiality or integrity.
Affected Systems
The vulnerability affects Oracle Helidon versions 4.0.0 through 4.5.4. Any instance of the helidon‑webserver component exposed to a network can be targeted without authorization.
Risk and Exploitability
With a CVSS score of 7.5, the flaw is considered high severity, but its EPSS score of less than 1% indicates that current automated exploitation attempts are very rare. It is not listed in CISA’s KEV catalog. An attacker requires only network access to the Helidon host and does not need credentials or special privileges, making exploitation straightforward for anyone who can reach the service over TCP.
OpenCVE Enrichment