ZeroHour

CVE-2026-83330

niche

Unauthenticated Denial-of-Service in Oracle Helidon 4.x WebSocket Component

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83330 is an easily exploitable flaw in the WebSocket component of Oracle Helidon, the open-source Java microservices framework that is part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access over HTTP can send crafted traffic — most plausibly malicious WebSocket handshakes or messages — that causes the Helidon service to hang or crash repeatedly, resulting in a complete denial of service. There is no impact on confidentiality or integrity; the sole impact is availability of Helidon-based applications. All deployments running Helidon versions 4.0.0 through 4.5.4 that expose HTTP/WebSocket endpoints are affected. The issue carries a CVSS 3.1 base score of 7.5; it is not in the CISA KEV catalog, no public proof-of-concept is known, and there is no indication of exploitation in the wild.

What to do: Upgrade Helidon to a release newer than 4.5.4 by applying Oracle's Critical Patch Update for Fusion Middleware. Until patched, restrict network access to WebSocket endpoints (VPN/IP allow-listing), rate-limit or filter HTTP upgrade requests at a reverse proxy or WAF, and monitor Helidon instances for repeated hangs or crashes that would indicate attempted exploitation.

Affected
Oracle Helidon (Oracle Fusion Middleware, WebSocket component)4.0.0 - 4.5.4
Estimated exposure
nichelikely low thousands of deployments worldwide; exact count unknown — Helidon is a relatively niche open-source Java microservices framework with no published active-install or internet-exposed device counts, and only services that expose HTTP/WebSocket endpoints are reachable, so the true exposed population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.