CVE-2024-8062
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.46%
- CWE
- CWE-1088
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- h2oai h2oai/h2o-3
Weakness type
Related vulnerabilities
- CVE-2026-81520 — MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion
- CVE-2025-4656 — Vault Vulnerable to Recovery Key Cancellation Denial of Service
- CVE-2024-12777 — Denial of Service in aimhubio/aim
- CVE-2024-8061 — Denial of Service in aimhubio/aim
- CVE-2020-14483 — A timeout during a TLS handshake can result in the connection failing to terminate. This can result...