15 Total advisories
15 Vulnerabilities
0 Malware
Dependency scanning
Check whether ai.h2o:h2o-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2024-10550
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
HIGH 7.5
CVE-2024-8062
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
HIGH 7.1
CVE-2024-6854
H2O Vulnerable to Arbitrary File Overwrite via File Export
MEDIUM 6.5
CVE-2024-6863
H2O Vulnerable to Execution of Arbitrary Files
HIGH 7.5
CVE-2024-7765
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
HIGH 7.5
CVE-2024-10549
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
HIGH 7.5
CVE-2024-7768
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
HIGH 8.2
CVE-2024-8616
H2O Vulnerable to Arbitrary File Overwrite
CRITICAL 9.1
CVE-2024-5986
H2O has an External Control of File Name or Path vulnerability
CRITICAL 9.1
CVE-2024-45758
H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
CRITICAL 9.8
CVE-2025-6544
H2O affected by a deserialization vulnerability
CRITICAL 9.8
CVE-2024-10553
H2O Deserialization of Untrusted Data Vulnerability
MEDIUM 5.9
CVE-2026-3960
H2O-3 is Vulnerable to Code Injection
HIGH 7.5
CVE-2024-6960
H2O vulnerable to Deserialization of Untrusted Data
CRITICAL 9.3
CVE-2023-6038
H2O local file inclusion vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes