CVE-2026-73890: High severity Oracle Helidon (Imperative Web Server) vulnerability
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Fusion Middleware Helidon (Imperative Web Server)to a version that resolves this vulnerability.Fixed in 4.4.1
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize Oracle Helidon deployments using the Imperative Web Server component on supported version 4.5.0, particularly where the service is reachable over HTTP/2.
Does exploitation require an authenticated account or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access via HTTP/2, with no user interaction required.
What is the expected impact of a successful attack?
Successful exploitation can cause Helidon to hang or repeatedly crash, resulting in a complete denial of service. The stated CVSS impacts are limited to availability, with no confidentiality or integrity impact listed.