Impact
A flaw in the Helidon JSON component allows an unauthenticated attacker with network access to deliver a crafted payload via HTTP, resulting in a partial denial of service. The compromise does not disclose sensitive data or enable further privileges; the attack impacts only the availability of the Helidon service. The CVSS v3.1 base score of 5.3 reflects this limited impact, scoring only availability as low.
Affected Systems
Versions of Oracle Helidon from 4.0.0 up to and including 4.5.4 are known to be vulnerable. These releases are part of Oracle Fusion Middleware and expose an HTTP endpoint for JSON processing.
Risk and Exploitability
The CVSS score indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack, as inferred from the description, would involve sending crafted JSON over the network; no special privileges or authentication are required.
OpenCVE Enrichment