Oracle Helidon vulnerabilities
104 known vulnerabilities affecting oracle/helidon.
Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH41MEDIUM44LOW2
Vulnerabilities
Page 3 of 6
CVE-2026-70908P3HIGHCVSS 7.5v3.2.182026-08-18
CVE-2026-70908 [HIGH] CWE-400 CVE-2026-70908: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2026-73927P3HIGHCVSS 7.5v3.2.202026-08-18
CVE-2026-73927 [HIGH] CWE-284 CVE-2026-73927: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2026-71153P3HIGHCVSS 7.5v1.4.202026-08-18
CVE-2026-71153 [HIGH] CWE-284 CVE-2026-71153: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2026-73882P3HIGHCVSS 7.5v3.2.192026-08-18
CVE-2026-73882 [HIGH] CWE-400 CVE-2026-73882: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2026-73902P3HIGHCVSS 7.5v3.2.192026-08-18
CVE-2026-73902 [HIGH] CWE-284 CVE-2026-73902: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2026-73934P3HIGHCVSS 7.5v3.2.192026-08-18
CVE-2026-73934 [HIGH] CWE-284 CVE-2026-73934: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-73891P3HIGHCVSS 7.3v4.5.02026-08-18
CVE-2026-73891 [HIGH] CWE-284 CVE-2026-73891: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inser
nvd
CVE-2026-73933P3HIGHCVSS 7.3v4.5.32026-08-18
CVE-2026-73933 [HIGH] CWE-284 CVE-2026-73933: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inser
nvd
CVE-2026-73936P3HIGHCVSS 7.5v4.5.12026-08-18
CVE-2026-73936 [HIGH] CWE-284 CVE-2026-73936: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2026-73935P3HIGHCVSS 7.5v4.5.12026-08-18
CVE-2026-73935 [HIGH] CWE-284 CVE-2026-73935: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-73890P3HIGHCVSS 7.5v4.5.02026-08-18
CVE-2026-73890 [HIGH] CWE-284 CVE-2026-73890: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-73915P3HIGHCVSS 7.5v4.5.02026-08-18
CVE-2026-73915 [HIGH] CWE-284 CVE-2026-73915: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2026-73875P3HIGHCVSS 7.2v3.2.192026-08-18
CVE-2026-73875 [HIGH] CWE-284 CVE-2026-73875: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact addition
nvd
CVE-2026-73885P3HIGHCVSS 7.2v3.2.182026-08-18
CVE-2026-73885 [HIGH] CWE-284 CVE-2026-73885: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact addition
nvd
CVE-2026-73876P3HIGHCVSS 7.2v4.5.12026-08-18
CVE-2026-73876 [HIGH] CWE-284 CVE-2026-73876: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additiona
nvd
CVE-2026-73886P3HIGHCVSS 7.2v4.5.02026-08-18
CVE-2026-73886 [HIGH] CWE-284 CVE-2026-73886: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additiona
nvd
CVE-2026-73928P3HIGHCVSS 7.2v4.5.32026-08-18
CVE-2026-73928 [HIGH] CWE-284 CVE-2026-73928: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additiona
nvd
CVE-2021-37136P3HIGHCVSS 7.5v1.4.10v2.4.02021-10-19
CVE-2021-37136 [HIGH] CWE-400 CVE-2021-37136: The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
nvd
CVE-2026-71162P3MEDIUMCVSS 6.5v3.2.182026-08-18
CVE-2026-71162 [MEDIUM] CWE-284 CVE-2026-71162: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access t
nvd
CVE-2026-71029P3MEDIUMCVSS 6.8≥ 3.0.0, ≤ 3.2.172026-08-18
CVE-2026-71029 [MEDIUM] CWE-284 CVE-2026-71029: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact addi
nvd