HIGH7.5
PYSEC-2026-1438
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
Details
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/h2o
Introduced in:
3.2.0.1No fixed version published yet for h2o (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-8062[ADVISORY]
- https://github.com/h2oai/h2o-3[PACKAGE]
- https://github.com/h2oai/h2o-3/blob/047a4d617240a56e74f834207c65973d133391cb/h2o-core/src/main/java/water/persist/PersistManager.java#L302[WEB]
- https://huntr.com/bounties/a04190d9-4acb-449a-9a7f-f1bf6be1ed23[WEB]
- https://pypi.org/project/h2o[PACKAGE]
- https://github.com/advisories/GHSA-5c8j-g96x-cj78[ADVISORY]