CVE-2026-87289: High severity Oracle Helidon vulnerability
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the unauthenticated network-accessible DoS risk by restricting inbound HTTP access to the Helidon service (e.g., limit exposure at the network/firewall/ACL level) until Helidon is updated.
Event History
Frequently Asked Questions
Which Helidon versions are affected?
Affected supported versions are 4.0.0 through 4.5.4.
What attacker access is required for exploitation?
An unauthenticated attacker needs network access to the affected Helidon instance via HTTP. No privileges or user interaction are required.