CVE-2026-83280
nicheUnauthenticated HTTP/2 Denial of Service in Oracle Helidon 4.x
CVE-2026-83280 is a denial-of-service flaw in the helidon-webserver-http2 component of Oracle Helidon, part of Oracle Fusion Middleware, affecting versions 4.0.0 through 4.5.4. An unauthenticated remote attacker who can reach the Helidon web server over the network via HTTP/2 can send crafted requests that cause the server to hang or repeatedly crash, resulting in a complete denial of service. The vulnerability is rated 7.5 (high) on CVSS 3.1, with network attack vector, low attack complexity, no privileges or user interaction required, and high availability impact only (no confidentiality or integrity impact). Any organization running an affected Helidon 4.x release with the HTTP/2-enabled web server exposed to clients or untrusted networks is affected. No public proof-of-concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog as of this writing.
What to do: Upgrade Helidon to a release newer than 4.5.4 that contains the fix from Oracle's Critical Patch Update as soon as possible. Until patched, restrict network access to Helidon HTTP/2 listeners (e.g., via firewall rules or an API gateway) or disable HTTP/2 in the webserver configuration, and monitor for hangs or repeated crashes indicative of abuse.
| Oracle Helidon (Fusion Middleware, component: helidon-webserver-http2) | 4.0.0 - 4.5.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.