Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Partial Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the Helidon JSON component allows an unauthenticated attacker with network access to deliver a crafted payload via HTTP, resulting in a partial denial of service. The compromise does not disclose sensitive data or enable further privileges; the attack impacts only the availability of the Helidon service. The CVSS v3.1 base score of 5.3 reflects this limited impact, scoring only availability as low.

Affected Systems

Versions of Oracle Helidon from 4.0.0 up to and including 4.5.4 are known to be vulnerable. These releases are part of Oracle Fusion Middleware and expose an HTTP endpoint for JSON processing.

Risk and Exploitability

The CVSS score indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack, as inferred from the description, would involve sending crafted JSON over the network; no special privileges or authentication are required.

Generated by OpenCVE AI on September 20, 2026 at 06:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle Helidon to a version that contains the patch for this issue, such as any release newer than 4.5.4.
  • Restrict external access to the Helidon HTTP endpoint by configuring firewalls or network ACLs to allow only trusted hosts.
  • Implement application‑level monitoring to detect abnormal traffic patterns or repeated denial‑of‑service attempts and trigger alerts or auto‑scale remediation.

Generated by OpenCVE AI on September 20, 2026 at 06:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Helidon JSON Component Partial Denial of Service Vulnerability

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Helidon JSON Component
Weaknesses CWE-20
CWE-399

Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Helidon JSON Component
Weaknesses CWE-20
CWE-399

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T16:14:12.921Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83458

cve-icon Vulnrichment

Updated: 2026-09-18T16:11:49.200Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:54.600

Modified: 2026-09-28T15:20:38.680

Link: CVE-2026-83458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption