cbcvebase.

Oracle Helidon vulnerabilities

104 known vulnerabilities affecting oracle/helidon.

Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH41MEDIUM44LOW2

Vulnerabilities

Page 4 of 6
CVE-2026-73867P3MEDIUMCVSS 6.5v3.2.182026-08-18
CVE-2026-73867 [MEDIUM] CWE-284 CVE-2026-73867: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, in
nvd
CVE-2026-73893P3MEDIUMCVSS 6.5v4.5.02026-08-18
CVE-2026-73893 [MEDIUM] CWE-284 CVE-2026-73893: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73868P3MEDIUMCVSS 6.5v4.5.02026-08-18
CVE-2026-73868 [MEDIUM] CWE-284 CVE-2026-73868: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73897P3MEDIUMCVSS 6.5v4.5.02026-08-18
CVE-2026-73897 [MEDIUM] CWE-284 CVE-2026-73897: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73904P3MEDIUMCVSS 6.5v4.5.12026-08-18
CVE-2026-73904 [MEDIUM] CWE-284 CVE-2026-73904: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73892P3MEDIUMCVSS 6.5v4.5.02026-08-18
CVE-2026-73892 [MEDIUM] CWE-284 CVE-2026-73892: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73896P3MEDIUMCVSS 6.5v4.5.02026-08-18
CVE-2026-73896 [MEDIUM] CWE-284 CVE-2026-73896: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read acce
nvd
CVE-2026-73914P3MEDIUMCVSS 6.5v4.5.02026-08-18
CVE-2026-73914 [MEDIUM] CWE-284 CVE-2026-73914: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-70716P3MEDIUMCVSS 5.9v4.5.02026-08-18
CVE-2026-70716 [MEDIUM] CWE-284 CVE-2026-70716: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2026-73909P3MEDIUMCVSS 5.9v3.2.192026-08-18
CVE-2026-73909 [MEDIUM] CWE-284 CVE-2026-73909: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access t
nvd
CVE-2021-21409P3MEDIUMCVSS 5.9v1.4.10v2.4.02021-03-30
CVE-2021-21409 [MEDIUM] CWE-444 CVE-2021-21409: Netty is an open-source, asynchronous event-driven network application framework for rapid developme Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the requ
nvd
CVE-2021-29425P3MEDIUMCVSS 4.8v1.4.7v2.2.02021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2021-43797P3MEDIUMCVSS 6.5v1.4.10v2.4.02021-12-09
CVE-2021-43797 [MEDIUM] CWE-444 CVE-2021-43797: Netty is an asynchronous event-driven network application framework for rapid development of maintai Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead
nvd
CVE-2026-73906P4MEDIUMCVSS 5.3v4.5.02026-08-18
CVE-2026-73906 [MEDIUM] CWE-284 CVE-2026-73906: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-73888P4MEDIUMCVSS 5.3v4.5.02026-08-18
CVE-2026-73888 [MEDIUM] CWE-284 CVE-2026-73888: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-71157P4MEDIUMCVSS 5.3v4.5.02026-08-18
CVE-2026-71157 [MEDIUM] CWE-284 CVE-2026-71157: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-73899P4MEDIUMCVSS 5.3v3.2.192026-08-18
CVE-2026-73899 [MEDIUM] CWE-284 CVE-2026-73899: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2026-73877P4MEDIUMCVSS 5.3v3.2.182026-08-18
CVE-2026-73877 [MEDIUM] CWE-284 CVE-2026-73877: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2026-73895P4MEDIUMCVSS 5.3v3.2.182026-08-18
CVE-2026-73895 [MEDIUM] CWE-284 CVE-2026-73895: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2026-70727P4MEDIUMCVSS 5.3v3.2.182026-08-18
CVE-2026-70727 [MEDIUM] CWE-284 CVE-2026-70727: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read acce
nvd
Oracle Helidon vulnerabilities | cvebase