Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

H2o HIGH 7.5
CVE-2026-54340

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combin…

Fix: 2026-06-04+
Fix from $1,950 2026-07-17
Quicly HIGH 7.5
CVE-2026-44435

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure i…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
Quicly HIGH 7.5
CVE-2026-44436

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable t…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
H2o HIGH 7.5
CVE-2026-44453

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when cal…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
H2o MEDIUM 5.9
CVE-2026-44452

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC…

Fix: 2026-05-29+
Fix from $1,600 2026-07-16
Quicly HIGH 7.5
CVE-2026-44433

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer co…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
Quicly MEDIUM 5.3
CVE-2026-44434

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable …

Fix: 2026-05-29+
Fix from $1,600 2026-07-16
H2o MEDIUM 5.3
CVE-2026-8752

A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapid…

Fix: after 7402
Fix from $1,600 2026-05-17
H2o CRITICAL 9.8
CVE-2026-8751

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod…

Fix: after 7402
Fix from $2,300 2026-05-17
H2o HIGH 7.5
CVE-2026-8750

A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water…

Fix: after 7402
Fix from $1,950 2026-05-17
H2o CRITICAL 9.8
CVE-2026-3960

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior…

Fix: 3.46.0.10+
Fix from $2,300 2026-04-23
Quicly HIGH 7.5
CVE-2025-61684

Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. …

Fix: 2026-01-18+
Fix from $1,950 2026-01-19
H2o CRITICAL 9.8
CVE-2025-10768

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB…

Fix: after 3.46.0.8
Fix from $2,300 2025-09-21
H2o CRITICAL 9.8
CVE-2025-10769

A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC…

Fix: after 3.46.0.8
Fix from $2,300 2025-09-21
H2o CRITICAL 9.8
CVE-2025-6544

A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary c…

Fix: after 3.46.0.8
Fix from $2,300 2025-09-21
H2o HIGH 8.2
CVE-2024-8616

In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability aris…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-8062

A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to ver…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-7768

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a …

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-7765

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The s…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.1
CVE-2024-6854

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any…

No fix yet
Fix from $1,950 2025-03-20
H2o MEDIUM 6.5
CVE-2024-6863

In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key o…

No fix yet
Fix from $1,600 2025-03-20
H2o CRITICAL 9.8
CVE-2024-10553

A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization o…

Patch available
Fix from $2,300 2025-03-20
H2o HIGH 7.5
CVE-2024-10549

A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-spec…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-10550

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a u…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-10572

In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGB…

No fix yet
Fix from $1,950 2025-03-20
H2o CRITICAL 9.8
CVE-2024-8862

A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the f…

No fix yet
Fix from $2,300 2024-09-14
H2o CRITICAL 9.1
CVE-2024-45758

H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. …

Fix: after 3.46.0.4
Fix from $2,300 2024-09-06
H2o HIGH 7.5
CVE-2024-5979

In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` names…

Patch available
Fix from $1,950 2024-06-27
H2o MEDIUM 5.3
CVE-2024-5550

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulne…

No fix yet
Fix from $1,600 2024-06-06
H2o HIGH 7.1
CVE-2024-1456

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-train…

No fix yet
Fix from $1,950 2024-04-16