Helidon vulnerabilities
CVEs whose affected-version data names the Helidon package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2026-87289High· 7.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-83488Medium· 5.4Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with netw…
CVE-2026-83480Medium· 5.3Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…
CVE-2026-83460Medium· 6.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to co…
CVE-2026-83459Medium· 5.3Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affected are 3.0.0-3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network …
CVE-2026-83458Medium· 5.3Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to c…
CVE-2026-83439High· 8.1Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Easily exploitable vulnerability allows low pri…
CVE-2026-83330High· 7.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…
CVE-2026-83281High· 7.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access …
CVE-2026-83280High· 7.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network a…
CVE-2026-83278Medium· 6.8Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated a…
CVE-2026-83276High· 7.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network a…
CVE-2026-83231High· 7.0Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated att…
CVE-2026-71029Medium· 6.8Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network …
CVE-2021-29425Medium· 4.8PoCIn Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…