Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A resource exhaustion flaw exists in the Helidon web server’s static content component that allows an unauthenticated remote attacker to trigger a crash or hang, leading to a complete denial of service. The vulnerability is mapped to CWE‑400 and can be exploited by sending specially crafted HTTP requests to the exposed static content endpoint. A successful attack removes the availability of the Helidon service for legitimate users. The impact is confined to availability; confidentiality and integrity are not directly affected.

Affected Systems

Oracle Helidon versions from 4.0.0 through 4.5.4 are affected. The flaw resides in the helidon‑webserver‑static‑content module, which is part of the Oracle Fusion Middleware product line.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity, and the vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H shows that no authentication or user interaction is required. The EPSS score is listed as <1%, suggesting a low probability of exploitation in the wild, yet the vulnerability is present in a public‑facing HTTP interface. Because the attack only requires network access and does not require administrative privileges, it is likely to be exploitably underway if a patch is not applied. The vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 18, 2026 at 13:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Oracle Helidon to the latest patched version (4.5.5 or newer) following the Oracle security advisory.
  • Apply the security patch according the procedures outlined in the referenced Oracle documentation.
  • If an immediate update is not feasible, limit HTTP exposure to known trusted networks or implement rate‑limiting and traffic filtering on the Helidon static content endpoints to mitigate the risk of a denial of service.

Generated by OpenCVE AI on September 18, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Helidon WebServer Static Content Denial of Service Vulnerability

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:51.751Z

Reserved: 2026-09-08T21:49:12.409Z

Link: CVE-2026-87289

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:22.976Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:18.897

Modified: 2026-09-25T19:35:48.140

Link: CVE-2026-87289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T01:00:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption