h2o has 12 CVEs on record between 2024 and 2026. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- h2o 12
Worst active — by depth score
CVE-2026-3960Critical· 9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…54CVE-2024-8616High· 8.2H2O Vulnerable to Arbitrary File Overwrite45CVE-2024-8062High· 7.5H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request41CVE-2024-7768High· 7.5H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint41CVE-2024-7765High· 7.5H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing41
h2o vulnerabilities
CVEs affecting h2o, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-3960Critical· 9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…
CVE-2024-10549High· 7.5H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-10572High· 7.5H2O Vulnerable to Denial of Service (DoS) and File Write
H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-7768High· 7.5H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
CVE-2024-6863Medium· 6.5H2O Vulnerable to Execution of Arbitrary Files
H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-8616High· 8.2H2O Vulnerable to Arbitrary File Overwrite
H2O Vulnerable to Arbitrary File Overwrite
CVE-2024-10550High· 7.5H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-7765High· 7.5H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-8062High· 7.5H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-6854High· 7.1H2O Vulnerable to Arbitrary File Overwrite via File Export
H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-5979High· 7.5h2o vulnerable to unexpected POST request shutting down server
h2o vulnerable to unexpected POST request shutting down server
CVE-2024-5550Medium· 5.3Arbitrary system path lookup in h20
Arbitrary system path lookup in h20