HIGH7.5
PYSEC-2026-1437
h2o vulnerable to unexpected POST request shutting down server
Details
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial of service.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/h2o
Introduced in:
0No fixed version published yet for h2o (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-5979[ADVISORY]
- https://github.com/h2oai/h2o-3/commit/d0899f8e0f7a584b60405a65b1d7b439aaaa55a5[WEB]
- https://github.com/h2oai/h2o-3[PACKAGE]
- https://huntr.com/bounties/d80a2139-fc03-44b7-b739-de41e323b458[WEB]
- https://pypi.org/project/h2o[PACKAGE]
- https://github.com/advisories/GHSA-58m3-rcvp-f9ww[ADVISORY]