Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6929 | A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests. |
Github GHSA |
GHSA-5c8j-g96x-cj78 | H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request |
Wed, 26 Mar 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H2o
H2o h2o |
|
| CPEs | cpe:2.3:a:h2o:h2o:3.46.0:*:*:*:*:*:*:* | |
| Vendors & Products |
H2o
H2o h2o |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests. | |
| Title | Denial of Service in h2oai/h2o-3 | |
| Weaknesses | CWE-1088 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T15:23:28.917Z
Reserved: 2024-08-21T18:58:51.164Z
Link: CVE-2024-8062
Updated: 2025-03-20T15:23:18.706Z
Status : Analyzed
Published: 2025-03-20T10:15:40.627
Modified: 2025-03-26T16:10:51.357
Link: CVE-2024-8062
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA