Impact
A resource exhaustion flaw exists in the Helidon web server’s static content component that allows an unauthenticated remote attacker to trigger a crash or hang, leading to a complete denial of service. The vulnerability is mapped to CWE‑400 and can be exploited by sending specially crafted HTTP requests to the exposed static content endpoint. A successful attack removes the availability of the Helidon service for legitimate users. The impact is confined to availability; confidentiality and integrity are not directly affected.
Affected Systems
Oracle Helidon versions from 4.0.0 through 4.5.4 are affected. The flaw resides in the helidon‑webserver‑static‑content module, which is part of the Oracle Fusion Middleware product line.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity, and the vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H shows that no authentication or user interaction is required. The EPSS score is listed as <1%, suggesting a low probability of exploitation in the wild, yet the vulnerability is present in a public‑facing HTTP interface. Because the attack only requires network access and does not require administrative privileges, it is likely to be exploitably underway if a patch is not applied. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment