H2O-3GHSA-58m3-rcvp-f9ww
h2o vulnerable to unexpected POST request shutting down server
High7.5CVE-2024-5979 · Published Jun 27, 2024 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| h2o PyPI | <= 3.46.0 | No fix yet |
Details and references
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial of service.
More H2O-3 advisories
All H2O-3| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 62024 | Arbitrary system path lookup in h20 CVE-2024-5550Medium5.3no fix yet | Medium5.3 | No fix yet |
| Sep 62024 | H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL CVE-2024-45758Critical9.1no fix yet | Critical9.1 | No fix yet |
| Dec 142023 | External Control of File Name or Path in h2oai/h2o-3 CVE-2023-6569Critical9.3fixed in 3.46.0.1 | Critical9.3 | 3.46.0.1 |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint CVE-2024-10550High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Deserialization of Untrusted Data Vulnerability CVE-2024-10553Critical9.8fixed in 3.46.0.6 | Critical9.8 | 3.46.0.6 |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) and File Write CVE-2024-10572High7.5no fix yet | High7.5 | No fix yet |