Impact
The Helidon WebSocket component in Oracle Fusion Middleware contains an unauthenticated HTTP endpoint that allows an attacker to open a large number of WebSocket connections without credentials. This uncontrolled connection creation leads to resource exhaustion, causing a partial denial of service and reducing Helidon’s availability. The weakness is identified as a resource exhaustion flaw (CWE‑400) and does not grant code execution or confidentiality compromise.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.4 are affected. The impact applies to deployments where the vulnerable WebSocket endpoint is exposed over HTTP and can be reached by unauthenticated users.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 points to moderate risk focused on availability. An EPSS score of <1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the attack requires only unauthenticated network access over HTTP, organizations should consider restricting or rate‑limiting the WebSocket endpoint until an official fix is published.
OpenCVE Enrichment