Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Helidon’s web server contains a resource exhaustion flaw that can be triggered by an unauthenticated TCP connection. The bug allows an attacker to make the service hang or crash repeatedly, leading to a full denial of service. The weakness is a classic example of a CWE‑400 input‑sized resource exhaustion vulnerability, with no impact on confidentiality or integrity.

Affected Systems

The vulnerability affects Oracle Helidon versions 4.0.0 through 4.5.4. Any instance of the helidon‑webserver component exposed to a network can be targeted without authorization.

Risk and Exploitability

With a CVSS score of 7.5, the flaw is considered high severity, but its EPSS score of less than 1% indicates that current automated exploitation attempts are very rare. It is not listed in CISA’s KEV catalog. An attacker requires only network access to the Helidon host and does not need credentials or special privileges, making exploitation straightforward for anyone who can reach the service over TCP.

Generated by OpenCVE AI on September 18, 2026 at 18:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Helidon to a version newer than 4.5.4 or apply any vendor‑supplied patch that resolves the resource exhaustion issue.
  • Configure firewall or security groups to limit inbound TCP traffic to Helidon only from trusted networks or IP addresses.
  • Continuously monitor Helidon logs for abnormal shutdowns or repeated crash cycles and ensure the service is automatically restarted when it fails.

Generated by OpenCVE AI on September 18, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Resource Exhaustion Leading to Application Hang or Crash

Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Resource Exhaustion Leading to Application Hang or Crash

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:53.436Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83281

cve-icon Vulnrichment

Updated: 2026-09-15T23:13:00.972Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:40.700

Modified: 2026-09-28T15:14:49.800

Link: CVE-2026-83281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:45:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption