CVE-2026-83276
nicheUnauthenticated HTTP/2 Denial of Service in Oracle Helidon 4.0.0-4.5.4
CVE-2026-83276 is a denial-of-service vulnerability in Oracle Helidon (Fusion Middleware), specifically in the helidon-webclient-http2 component, affecting versions 4.0.0 through 4.5.4. An unauthenticated attacker with network access can send crafted HTTP/2 traffic to trigger a hang or frequently repeatable crash, completely denying service to the Helidon-based application. The flaw is rated easily exploitable (CVSS 3.1 base score 7.5) but impacts availability only — there is no impact on confidentiality or integrity. Any organization running a Helidon 4.x service in the affected range with HTTP/2 reachable over the network is at risk. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is presumed unlikely at this time.
What to do: Upgrade all Helidon 4.x instances in the 4.0.0-4.5.4 range to a fixed release above 4.5.4 as provided by Oracle's Critical Patch Update. Where patching must be delayed, restrict network reachability of Helidon services (especially HTTP/2 listeners) to trusted clients via firewalls or reverse proxies, or disable HTTP/2 where the application allows it. Monitor Helidon processes for unexplained hangs, repeated crashes, and abnormal HTTP/2 connection patterns.
| Oracle Helidon (Oracle Fusion Middleware, component: helidon-webclient-http2) | 4.0.0 - 4.5.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.