HIGH 7.5 PyPI
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
GHSA-7qq7-pvm9-x8rf · CVE-2024-10550 · PYSEC-2026-1440
Published · Modified
Description
A vulnerability in the /3/ParseSetup endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-10550
- PACKAGE https://github.com/h2oai/h2o-3
- WEB https://github.com/h2oai/h2o-3/blob/51c25940ded8b7d0acc8f3f72329fd9dedbb3a34/h2o-core/src/main/java/water/api/ParseSetupHandler.java#L121
- WEB https://huntr.com/bounties/ef3f4d89-3b8b-4618-b134-cb93c1664ec6
Ready to move
Start Securing
Free, no credit card | First findings in minutes