ZeroHour

CVE-2026-83281

niche

Unauthenticated TCP Denial-of-Service in Oracle Helidon WebServer 4.x

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83281 is an easily exploitable denial-of-service flaw in the helidon-webserver component of Oracle Helidon, part of Oracle Fusion Middleware. An unauthenticated remote attacker who can reach the server over TCP can send crafted requests that cause the Helidon instance to hang or crash repeatedly, resulting in complete denial of service. The vulnerability affects only availability; there is no impact on confidentiality or integrity (CVSS 3.1 base score 7.5). All supported Helidon versions from 4.0.0 through 4.5.4 are affected, so any deployment of Helidon 4.x running the webserver is at risk if its ports are network-reachable. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known, though the low attack complexity makes reliable DoS trivial once a target is identified.

What to do: Upgrade Helidon to a release newer than 4.5.4 as provided in Oracle's Critical Patch Update guidance. Until patched, restrict TCP access to Helidon webserver ports to trusted networks via firewall rules and rate-limit connections, and monitor instances for unexplained hangs or repeated crashes that would indicate DoS attempts. Inventory any Java services built on Helidon 4.0.0-4.5.4 and confirm whether their listening endpoints are network-reachable.

Affected
Oracle Helidon (Fusion Middleware, component: helidon-webserver)4.0.0 - 4.5.4
Estimated exposure
nicheunknown; likely low thousands of deployments at most, predominantly internal Java microservices — Helidon is a niche Oracle open-source Java microservices framework with far smaller adoption than mainstream servers (e.g., Tomcat/Spring Boot), and instances are typically deployed as internal or cloud-internal services rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.