CVE-2026-83330
nicheUnauthenticated Denial-of-Service in Oracle Helidon 4.x WebSocket Component
CVE-2026-83330 is an easily exploitable flaw in the WebSocket component of Oracle Helidon, the open-source Java microservices framework that is part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access over HTTP can send crafted traffic — most plausibly malicious WebSocket handshakes or messages — that causes the Helidon service to hang or crash repeatedly, resulting in a complete denial of service. There is no impact on confidentiality or integrity; the sole impact is availability of Helidon-based applications. All deployments running Helidon versions 4.0.0 through 4.5.4 that expose HTTP/WebSocket endpoints are affected. The issue carries a CVSS 3.1 base score of 7.5; it is not in the CISA KEV catalog, no public proof-of-concept is known, and there is no indication of exploitation in the wild.
What to do: Upgrade Helidon to a release newer than 4.5.4 by applying Oracle's Critical Patch Update for Fusion Middleware. Until patched, restrict network access to WebSocket endpoints (VPN/IP allow-listing), rate-limit or filter HTTP upgrade requests at a reverse proxy or WAF, and monitor Helidon instances for repeated hangs or crashes that would indicate attempted exploitation.
| Oracle Helidon (Oracle Fusion Middleware, WebSocket component) | 4.0.0 - 4.5.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.