CVE-2026-83281
nicheUnauthenticated TCP Denial-of-Service in Oracle Helidon WebServer 4.x
CVE-2026-83281 is an easily exploitable denial-of-service flaw in the helidon-webserver component of Oracle Helidon, part of Oracle Fusion Middleware. An unauthenticated remote attacker who can reach the server over TCP can send crafted requests that cause the Helidon instance to hang or crash repeatedly, resulting in complete denial of service. The vulnerability affects only availability; there is no impact on confidentiality or integrity (CVSS 3.1 base score 7.5). All supported Helidon versions from 4.0.0 through 4.5.4 are affected, so any deployment of Helidon 4.x running the webserver is at risk if its ports are network-reachable. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known, though the low attack complexity makes reliable DoS trivial once a target is identified.
What to do: Upgrade Helidon to a release newer than 4.5.4 as provided in Oracle's Critical Patch Update guidance. Until patched, restrict TCP access to Helidon webserver ports to trusted networks via firewall rules and rate-limit connections, and monitor instances for unexplained hangs or repeated crashes that would indicate DoS attempts. Inventory any Java services built on Helidon 4.0.0-4.5.4 and confirm whether their listening endpoints are network-reachable.
| Oracle Helidon (Fusion Middleware, component: helidon-webserver) | 4.0.0 - 4.5.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.