ZeroHour

CVE-2026-83276

niche

Unauthenticated HTTP/2 Denial of Service in Oracle Helidon 4.0.0-4.5.4

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83276 is a denial-of-service vulnerability in Oracle Helidon (Fusion Middleware), specifically in the helidon-webclient-http2 component, affecting versions 4.0.0 through 4.5.4. An unauthenticated attacker with network access can send crafted HTTP/2 traffic to trigger a hang or frequently repeatable crash, completely denying service to the Helidon-based application. The flaw is rated easily exploitable (CVSS 3.1 base score 7.5) but impacts availability only — there is no impact on confidentiality or integrity. Any organization running a Helidon 4.x service in the affected range with HTTP/2 reachable over the network is at risk. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is presumed unlikely at this time.

What to do: Upgrade all Helidon 4.x instances in the 4.0.0-4.5.4 range to a fixed release above 4.5.4 as provided by Oracle's Critical Patch Update. Where patching must be delayed, restrict network reachability of Helidon services (especially HTTP/2 listeners) to trusted clients via firewalls or reverse proxies, or disable HTTP/2 where the application allows it. Monitor Helidon processes for unexplained hangs, repeated crashes, and abnormal HTTP/2 connection patterns.

Affected
Oracle Helidon (Oracle Fusion Middleware, component: helidon-webclient-http2)4.0.0 - 4.5.4
Estimated exposure
nicheLikely on the order of hundreds to low thousands of deployments, many internal rather than internet-facing — Helidon is a relatively niche open-source Java microservices framework with limited adoption compared to mainstream stacks, and no public scan or install-count data specific to Helidon HTTP/2 endpoints was available, so this is a rough…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.