
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73936 is a denial-of-service vulnerability in the Imperative Web Server component of Oracle Helidon, part of Oracle Fusion Middleware. The vulnerability allows an unauthenticated remote attacker to cause the Helidon server to hang or crash repeatedly via crafted HTTP requests. Only version 4.5.1 is listed as the supported affected version, though the Oracle August 2026 CSPU advisory also lists additional Helidon versions (1.4.19, 1.4.20, 3.2.18–3.2.20, 4.5.0, 4.5.3) as receiving patches. It carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, Github Advisory). The vulnerability was disclosed on August 18, 2026, as part of Oracle's Critical Security Patch Update cycle.
The vulnerability is classified under CWE-284 (Improper Access Control), indicating that the Helidon Imperative Web Server component fails to properly restrict access to a resource or operation from unauthorized actors (Github Advisory). An unauthenticated attacker with network access over HTTP can send specially crafted requests that trigger a hang or repeatable crash of the server process. No authentication, user interaction, or elevated privileges are required, and the attack complexity is low, making it easily automatable (Oracle Advisory). No public technical write-ups or proof-of-concept code detailing the specific request structure have been identified at this time.
Successful exploitation results in complete unavailability of the Helidon web server — either through a persistent hang or a frequently repeatable crash — constituting a full denial-of-service condition. There is no impact on confidentiality or integrity; the vulnerability is purely an availability issue (Oracle Advisory). Applications and services relying on the affected Helidon Imperative Web Server instance would become inaccessible to legitimate users for the duration of the attack, with no lateral movement or data exposure risk identified.
CISA's SSVC assessment classifies this vulnerability as automatable with no known exploitation in the wild at the time of disclosure (Github Advisory). No public proof-of-concept exploit code has been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.44%, indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
Oracle has released patches for Helidon as part of the August 2026 Critical Security Patch Update; affected users should apply the patch immediately (Oracle Advisory). As a temporary workaround, Oracle recommends blocking network protocols required by the attack (HTTP access to the Helidon server) at the network perimeter to reduce exposure until patching is feasible. Additionally, implementing rate limiting, request validation, and restricting HTTP traffic to trusted sources can help reduce the attack surface. Oracle strongly advises against treating network-level controls as a long-term solution.
The vulnerability received brief coverage from automated threat intelligence aggregators and security news feeds shortly after disclosure, including mentions on The Hacker Wire and radar.offseq.com (Oracle Advisory). No notable independent researcher commentary or significant community discussion has been identified beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."