Denial of Service Vulnerability in h2oai/h2o-3 Product
CVE-2024-10550
7.5HIGH
What is CVE-2024-10550?
A vulnerability in the /3/ParseSetup endpoint of h2oai’s h2o-3 version 3.46.0.1 enables attackers to exploit user-defined regular expressions on user-controllable strings. By crafting specific inputs, malicious users can trigger excessive regular expression complexity, resulting in server resource exhaustion and leading to unresponsiveness. This vulnerability highlights the need for enhanced input validation and resource management to protect server integrity.
Affected Version(s)
h2oai/h2o-3 <= unspecified
References
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
