ZeroHour

CVE-2026-83280

niche

Unauthenticated HTTP/2 Denial of Service in Oracle Helidon 4.x

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83280 is a denial-of-service flaw in the helidon-webserver-http2 component of Oracle Helidon, part of Oracle Fusion Middleware, affecting versions 4.0.0 through 4.5.4. An unauthenticated remote attacker who can reach the Helidon web server over the network via HTTP/2 can send crafted requests that cause the server to hang or repeatedly crash, resulting in a complete denial of service. The vulnerability is rated 7.5 (high) on CVSS 3.1, with network attack vector, low attack complexity, no privileges or user interaction required, and high availability impact only (no confidentiality or integrity impact). Any organization running an affected Helidon 4.x release with the HTTP/2-enabled web server exposed to clients or untrusted networks is affected. No public proof-of-concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog as of this writing.

What to do: Upgrade Helidon to a release newer than 4.5.4 that contains the fix from Oracle's Critical Patch Update as soon as possible. Until patched, restrict network access to Helidon HTTP/2 listeners (e.g., via firewall rules or an API gateway) or disable HTTP/2 in the webserver configuration, and monitor for hangs or repeated crashes indicative of abuse.

Affected
Oracle Helidon (Fusion Middleware, component: helidon-webserver-http2)4.0.0 - 4.5.4
Estimated exposure
nichelikely on the order of hundreds to low thousands of internet-exposed deployments — Helidon is a niche open-source Java microservices framework with adoption far smaller than mainstream options like Spring Boot, most instances run embedded in applications and behind load balancers, and no public scan counts exist, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.