Skip to content
H2O-3GHSA-p2vc-m5fv-9w9m

H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint

High7.5CVE-2024-7768 · Published Mar 20, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
h2o
PyPI
<= 3.46.1No fix yet
Details and references

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-770
Also known as
CVE-2024-7768, PYSEC-2026-1443

More H2O-3 advisories

All H2O-3
DateAdvisory
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-10550High7.5no fix yet
Mar 202025H2O Deserialization of Untrusted Data Vulnerability
CVE-2024-10553Critical9.8fixed in 3.46.0.6
Mar 202025H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-10572High7.5no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-10549High7.5no fix yet
Mar 202025H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-6854High7.1no fix yet
Mar 202025H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-6863Medium6.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.