Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Partial Denial of Service
Action: Monitor
AI Analysis

Impact

The Helidon WebSocket component in Oracle Fusion Middleware contains an unauthenticated HTTP endpoint that allows an attacker to open a large number of WebSocket connections without credentials. This uncontrolled connection creation leads to resource exhaustion, causing a partial denial of service and reducing Helidon’s availability. The weakness is identified as a resource exhaustion flaw (CWE‑400) and does not grant code execution or confidentiality compromise.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.5.4 are affected. The impact applies to deployments where the vulnerable WebSocket endpoint is exposed over HTTP and can be reached by unauthenticated users.

Risk and Exploitability

The CVSS 3.1 base score of 5.3 points to moderate risk focused on availability. An EPSS score of <1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the attack requires only unauthenticated network access over HTTP, organizations should consider restricting or rate‑limiting the WebSocket endpoint until an official fix is published.

Generated by OpenCVE AI on September 20, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict Helidon HTTP access to trusted networks or apply IP filtering so that only authorized clients can reach the WebSocket endpoint.
  • Enforce authentication or configure connection limits on the WebSocket endpoint to prevent unbounded connection creation.
  • Monitor Helidon logs and network traffic for abnormal spikes in WebSocket activity, and apply firewall or rate‑limiting rules to contain potential denial‑of‑service attempts.
  • Check Oracle Helidon advisories and apply any released patches or updates that address this vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Helidon WebSocket Unauthenticated Endpoint Causes Resource Exhaustion Denial of Service

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Helidon WebSocket Component Allows Unauthenticated HTTP Clients to Trigger Partial Denial of Service
Weaknesses CWE-290

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Helidon WebSocket Component Allows Unauthenticated HTTP Clients to Trigger Partial Denial of Service
Weaknesses CWE-290

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T16:13:57.381Z

Reserved: 2026-08-31T15:40:57.361Z

Link: CVE-2026-83480

cve-icon Vulnrichment

Updated: 2026-09-18T16:11:48.140Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:55.697

Modified: 2026-09-25T19:27:37.587

Link: CVE-2026-83480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption