# CVE-2024-7765

## Summary

- **CVE ID:** CVE-2024-7765
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-409
- **Published:** Mar 20, 2025
- **Last Modified:** Mar 13, 2026

## Description

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running jobs. This issue arises from the improper handling of highly compressed data, leading to significant data amplification.

## Affected Products

- h2oai — h2oai/h2o-3 (unspecified)

## References

- [CNA](https://huntr.com/bounties/0e58b1a5-bdca-4e60-af92-09de9c76a9ff)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.75%
- **EPSS Percentile:** 53.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._