-Infinity
0

Vendor Risk Score

See how h2o compares to other vendors in security performance

View Risk Score →

h2o HTTP serverh2o has HTTP/2 state amplification

Risk 43
Severity
7.5
First published (updated )

h2o h2oh2o is vulnerable to heap overrun

Risk 35
Severity
5.9
First published (updated )

Quicly quiclyQuicly is vulnerable to connection state corruption

Risk 43
Severity
7.5
First published (updated )

h2o h2o HTTP serverh2o: musl libc stack overflow (QPACK)

Risk 43
Severity
7.5
First published (updated )

oss-secHTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

h2oai h2o-3h2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control

Risk 20
Severity
5.5
EPSS
0.31%
First published (updated )

H2O.ai H2O-3h2oai h2o-3 JAR Model.java importBinaryModel deserialization

Risk 61
Severity
5.5
EPSS
0.41%
First published (updated )

H2O.ai H2O-3h2oai h2o-3 ImportFile API PersistNFS.java importFiles information disclosure

Risk 31
Severity
5.5
EPSS
0.50%
First published (updated )

H2O.ai H2O-3Remote Code Execution in h2oai/h2o-3

Risk 86
Severity
9.8
First published (updated )

QuiclyQuicly has assertion failures

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

h2oai h2o-3h2oai h2o-3 H2 JDBC Driver ImportSQLTable deserialization

Risk 86
Severity
9.8
First published (updated )

h2oai h2o-3h2oai h2o-3 IBMDB2 JDBC Driver ImportSQLTable deserialization

Risk 86
Severity
9.8
First published (updated )

h2oai h2o-3Deserialization Vulnerability in h2oai/h2o-3

Risk 86
Severity
9.8
First published (updated )

h2oai h2o-3Denial of Service by ReDOS in h2oai/h2o-3

Risk 43
Severity
7.5
First published (updated )

h2oai h2o-3Denial of Service in h2oai/h2o-3

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

h2oai h2o-3Denial of Service in h2oai/h2o-3

Risk 43
Severity
7.5
First published (updated )

h2oai h2o-3Encryption of Arbitrary Files with Attacker-Controlled Key in h2oai/h2o-3

Risk 40
Severity
6.5
First published (updated )

h2oai h2o-3Arbitrary File Overwrite in h2oai/h2o-3

Risk 54
Severity
8.2
First published (updated )

h2oai h2o-3Denial of Service by ReDOS in h2oai/h2o-3

Risk 43
Severity
7.5
First published (updated )

h2oai h2o-3Arbitrary File Overwrite in h2oai/h2o-3

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

h2oai h2o-3Denial of Service and Arbitrary File Write in h2oai/h2o-3

Risk 43
Severity
7.5
First published (updated )

h2oai h2o-3Jdbc Deserialization in h2oai/h2o-3

Risk 86
Severity
9.8
First published (updated )

h2oai h2o-3Denial of Service in h2oai/h2o-3

Risk 43
Severity
7.5
First published (updated )

pip/dtaleh2oai h2o-3 JDBC Connection 1 getConnectionSafe deserialization

Risk 62
Severity
9.8
EPSS
0.29%
First published (updated )

H2O.ai H2OH2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserializa…

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/h2oDenial of Service via Invalid Argument in h2oai/h2o-3

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

pip/h2oExposure of Sensitive Information via Arbitrary System Path Lookup in h2oai/h2o-3

Risk 20
Severity
5.3
EPSS
0.04%
First published (updated )

h2o h2oS3 Bucket Takeover in h2oai/h2o-3

Risk 51
Severity
7.1
First published (updated )

pip/h2oExternal Control of File Name or Path in h2oai/h2o-3

Risk 43
Severity
9.3
EPSS
0.05%
First published (updated )

h2o h2oH2O Local File Include

Risk 43
Severity
9.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203