Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Availability (Denial of Service)
Action: Immediate Patch
AI Analysis

Impact

The Helidon WebSocket component in Oracle Fusion Middleware contains a flaw that permits an unauthenticated attacker with network access via HTTP to crash the Helidon application. The vulnerability is rooted in a weakness described by CWE-400, leading to significant disruption without compromising confidentiality or integrity.

Affected Systems

Oracle Helidon product versions 4.0.0 through 4.5.4 are affected. These versions are part of Oracle Fusion Middleware.

Risk and Exploitability

The EPSS score of under 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV. With a CVSS base score of 7.5, the flaw is considered high severity, primarily affecting availability. Unauthenticated attackers can reach the target over standard HTTP, making it potentially exploitable in environments with exposed Helidon services.

Generated by OpenCVE AI on September 18, 2026 at 15:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available update that addresses the WebSocket flaw.
  • If an immediate patch is not feasible, restrict or disable the Helidon WebSocket endpoints to trusted IP ranges using firewall or access control lists.
  • Continuously monitor Helidon logs and system metrics for repeated hangs or crashes, and investigate any anomalous WebSocket traffic.

Generated by OpenCVE AI on September 18, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Helidon WebSocket Denial of Service Vulnerability

Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Helidon WebSocket Denial of Service Vulnerability

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:53.284Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83330

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:57.709Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:46.207

Modified: 2026-09-28T15:15:31.267

Link: CVE-2026-83330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:45:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption