H2O-3GHSA-p2vc-m5fv-9w9m
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
High7.5CVE-2024-7768 · Published Mar 20, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| h2o PyPI | <= 3.46.1 | No fix yet |
Details and references
A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.
More H2O-3 advisories
All H2O-3| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint CVE-2024-10550High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Deserialization of Untrusted Data Vulnerability CVE-2024-10553Critical9.8fixed in 3.46.0.6 | Critical9.8 | 3.46.0.6 |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) and File Write CVE-2024-10572High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint CVE-2024-10549High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Arbitrary File Overwrite via File Export CVE-2024-6854High7.1no fix yet | High7.1 | No fix yet |
| Mar 202025 | H2O Vulnerable to Execution of Arbitrary Files CVE-2024-6863Medium6.5no fix yet | Medium6.5 | No fix yet |