CVE-2026-54340
- EPSS 0.28%
- Veröffentlicht 16.07.2026 23:29:50
- Zuletzt bearbeitet 05.08.2026 19:47:02
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. Amplified decoded header s...
CVE-2026-44453
- EPSS 0.28%
- Veröffentlicht 16.07.2026 23:16:17
- Zuletzt bearbeitet 06.08.2026 13:25:39
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, b...
CVE-2026-44452
- EPSS 0.25%
- Veröffentlicht 16.07.2026 23:16:17
- Zuletzt bearbeitet 06.08.2026 13:56:18
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while...
CVE-2026-55213
- EPSS 0.34%
- Veröffentlicht 10.07.2026 20:49:58
- Zuletzt bearbeitet 13.07.2026 19:24:52
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-stack buffer a...
CVE-2026-8752
- EPSS 0.31%
- Veröffentlicht 17.05.2026 11:45:11
- Zuletzt bearbeitet 19.05.2026 17:44:01
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing...
CVE-2026-8751
- EPSS 0.41%
- Veröffentlicht 17.05.2026 11:30:10
- Zuletzt bearbeitet 19.05.2026 17:46:04
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attac...
CVE-2026-8750
- EPSS 0.5%
- Veröffentlicht 17.05.2026 10:45:10
- Zuletzt bearbeitet 19.05.2026 18:22:34
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disc...
CVE-2026-3960
- EPSS 0.94%
- Veröffentlicht 23.04.2026 08:47:48
- Zuletzt bearbeitet 19.05.2026 21:52:42
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism...
CVE-2025-10769
- EPSS 0.49%
- Veröffentlicht 21.09.2025 09:33:19
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The attack may be...
CVE-2025-10768
- EPSS 0.4%
- Veröffentlicht 21.09.2025 09:33:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack ma...