CVE-2026-73937
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-73937 is a vulnerability in the Helidon product of Oracle Fusion Middleware, specifically affecting the Imperative Web Server component. It allows unauthenticated remote attackers to exploit the system via the HTTP/2 protocol, resulting in denial of service and partial information disclosure. Only version 4.5.0 of Oracle Helidon is confirmed affected. The vulnerability was disclosed on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026, and carries a CVSS v3.1 base score of 8.2 (High) (Oracle Advisory, Github Advisory).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control), indicating that the Helidon Imperative Web Server fails to properly restrict access to resources when processing HTTP/2 requests (Github Advisory). An unauthenticated attacker with network access can send crafted HTTP/2 requests to trigger a hang or crash of the Helidon service, and may also gain unauthorized read access to a subset of data accessible by the server. No authentication, user interaction, or elevated privileges are required, and attack complexity is low, making this easily exploitable from the network. No detailed technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).

Impact

Successful exploitation results in a complete denial of service — the Helidon server can be caused to hang or crash repeatedly — as well as unauthorized read access to a subset of data accessible by the Helidon instance. The availability impact is rated High and the confidentiality impact is rated Low, with no integrity impact. Because the attack requires no authentication and is network-accessible, any internet-facing Helidon 4.5.0 deployment is at risk of service disruption and potential data exposure (Oracle Advisory, Github Advisory).

Exploitability

As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (Github Advisory). CISA's SSVC assessment classifies the vulnerability as "automatable: yes" and "exploitation: none," indicating that while the attack can be automated, no exploitation has been observed (Oracle Advisory). The EPSS score is approximately 0.39%, placing it in the 32nd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Oracle has released a patch for this vulnerability as part of the August 2026 Critical Security Patch Update; users should upgrade Oracle Helidon from version 4.5.0 to a patched version as soon as possible (Oracle Advisory). As interim mitigations, restrict network access to the Helidon HTTP/2 service to trusted clients only, implement rate limiting and connection throttling to reduce denial-of-service impact, and monitor for unexpected crashes or hangs of Helidon services. Oracle strongly recommends applying security patches without delay rather than relying on network-level workarounds as a long-term solution.

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73939HIGH8.6
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73937HIGH8.2
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73938HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73936HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73935HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management