CVE-2025-6544: Deserialization Vulnerability in h2oai/h2o-3
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.7, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handling of JDBC connection parameters, which can be exploited by bypassing regular expression checks and using double URL encoding. This issue impacts all users of the affected versions.
Other sources
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handling of JDBC connection parameters, which can be exploited by bypassing regular expression checks and using double URL encoding. This issue impacts all users of the affected versions.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6544?
CVE-2025-6544 has a high severity rating due to its potential for remote code execution and disclosure of sensitive system files.
How do I fix CVE-2025-6544?
To fix CVE-2025-6544, upgrade to h2oai/h2o-3 version 3.46.0.9 or later where the deserialization vulnerability has been addressed.
What vulnerabilities does CVE-2025-6544 introduce?
CVE-2025-6544 introduces vulnerabilities that allow attackers to read arbitrary system files and execute arbitrary code.
Which versions of h2o-3 are affected by CVE-2025-6544?
CVE-2025-6544 affects all h2oai/h2o-3 versions up to and including 3.46.0.8.
What causes the CVE-2025-6544 vulnerability?
The CVE-2025-6544 vulnerability is caused by improper handling of JDBC connection parameters leading to deserialization issues.