33 Total advisories
33 Vulnerabilities
0 Malware

Dependency scanning

Check whether h2o is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2026-3960

CVE-2026-3960

HIGH 7.5
PyPI

CVE-2024-10572

H2O Vulnerable to Denial of Service (DoS) and File Write

HIGH 7.5
PyPI

CVE-2024-10550

H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint

HIGH 7.5
PyPI

CVE-2024-8062

H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request

HIGH 7.1
PyPI

CVE-2024-6854

H2O Vulnerable to Arbitrary File Overwrite via File Export

MEDIUM 6.5
PyPI

CVE-2024-6863

H2O Vulnerable to Execution of Arbitrary Files

HIGH 7.5
PyPI

CVE-2024-7765

H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing

HIGH 7.5
PyPI

CVE-2024-10549

H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint

MEDIUM 5.3
PyPI

CVE-2024-5550

Arbitrary system path lookup in h20

HIGH 7.5
PyPI

CVE-2024-7768

H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint

HIGH 7.5
PyPI

CVE-2024-5979

h2o vulnerable to unexpected POST request shutting down server

HIGH 8.2
PyPI

CVE-2024-8616

H2O Vulnerable to Arbitrary File Overwrite

HIGH 7.5
PyPI

CVE-2024-8062

H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request

HIGH 7.5
PyPI

CVE-2024-7765

H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing

HIGH 7.1
PyPI

CVE-2024-6854

H2O Vulnerable to Arbitrary File Overwrite via File Export

HIGH 7.5
PyPI

CVE-2024-5979

h2o vulnerable to unexpected POST request shutting down server

MEDIUM 5.3
PyPI

CVE-2024-5550

Arbitrary system path lookup in h20

HIGH 7.5
PyPI

CVE-2024-10549

H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint

HIGH 7.5
PyPI

CVE-2024-10550

H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint

HIGH 8.2
PyPI

CVE-2024-8616

H2O Vulnerable to Arbitrary File Overwrite

HIGH 7.5
PyPI

CVE-2024-10572

H2O Vulnerable to Denial of Service (DoS) and File Write

MEDIUM 6.5
PyPI

CVE-2024-6863

H2O Vulnerable to Execution of Arbitrary Files

HIGH 7.5
PyPI

CVE-2024-7768

H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint

CRITICAL 9.1
PyPI

CVE-2024-5986

H2O has an External Control of File Name or Path vulnerability

CRITICAL 9.1
PyPI

CVE-2024-45758

H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL

CRITICAL 9.8
PyPI

CVE-2024-10553

H2O Deserialization of Untrusted Data Vulnerability

CRITICAL 9.3
PyPI

CVE-2023-6569

External Control of File Name or Path in h2oai/h2o-3

CRITICAL 9.8
PyPI

CVE-2025-6544

H2O affected by a deserialization vulnerability

CRITICAL 9.1
Maven

CVE-2024-5986

H2O has an External Control of File Name or Path vulnerability

CRITICAL 9.1
Maven

CVE-2024-45758

H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL

CRITICAL 9.8
Maven

CVE-2025-6544

H2O affected by a deserialization vulnerability

CRITICAL 9.8
PyPI

CVE-2024-10553

H2O Deserialization of Untrusted Data Vulnerability

CRITICAL 9.3
PyPI

CVE-2023-6569

External Control of File Name or Path in h2oai/h2o-3

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes