Dependency scanning
Check whether h2o is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-3960
CVE-2026-3960
CVE-2024-10572
H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-10550
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-8062
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-6854
H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-6863
H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-7765
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-10549
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-5550
Arbitrary system path lookup in h20
CVE-2024-7768
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
CVE-2024-5979
h2o vulnerable to unexpected POST request shutting down server
CVE-2024-8616
H2O Vulnerable to Arbitrary File Overwrite
CVE-2024-8062
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-7765
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-6854
H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-5979
h2o vulnerable to unexpected POST request shutting down server
CVE-2024-5550
Arbitrary system path lookup in h20
CVE-2024-10549
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-10550
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-8616
H2O Vulnerable to Arbitrary File Overwrite
CVE-2024-10572
H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-6863
H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-7768
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
CVE-2024-5986
H2O has an External Control of File Name or Path vulnerability
CVE-2024-45758
H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
CVE-2024-10553
H2O Deserialization of Untrusted Data Vulnerability
CVE-2023-6569
External Control of File Name or Path in h2oai/h2o-3
CVE-2025-6544
H2O affected by a deserialization vulnerability
CVE-2024-5986
H2O has an External Control of File Name or Path vulnerability
CVE-2024-45758
H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
CVE-2025-6544
H2O affected by a deserialization vulnerability
CVE-2024-10553
H2O Deserialization of Untrusted Data Vulnerability
CVE-2023-6569
External Control of File Name or Path in h2oai/h2o-3
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes