Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

h2o — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting h2o. AI-powered Chinese analysis, POCs, and references for each vulnerability.

H2o serves as an open-source machine learning platform primarily used for training and deploying predictive models. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure deserialization. The platform's Java-based architecture and web interface have contributed to these security issues. While no major public security incidents have been widely reported, the 10 documented CVEs highlight consistent security challenges, particularly in authentication and data handling components. Organizations implementing H2o should prioritize regular updates and input sanitization to mitigate these recurring risks.

Top products by h2o: h2o quicly picotls
CVE ID Title CVSS Severity Published
CVE-2026-45271 picotls has infinite recursion in the minicrypto ASN.1 decoder — picotls CWE-835 5.5 Medium 2026-08-21
CVE-2026-54340 h2o has HTTP/2 state amplification — h2o CWE-400 7.5 High 2026-07-16
CVE-2026-44453 h2o is vulnerable to musl libc stack overflow — h2o CWE-789 7.5 High 2026-07-16
CVE-2026-44452 h2o is vulnerable to heap overrun — h2o CWE-125 5.9 Medium 2026-07-16
CVE-2026-44436 Quicly is vulnerable to connection state corruption — quicly CWE-120 7.5 High 2026-07-16
CVE-2026-44435 Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB — quicly CWE-617 7.5 High 2026-07-16
CVE-2026-44434 Quicly is vulnerable to stateless reset injection — quicly CWE-345 5.3 Medium 2026-07-16
CVE-2026-44433 Quicly is vulnerable to memory exhaustion — quicly CWE-770 5.3 Medium 2026-07-16
CVE-2026-55213 h2o: musl libc stack overflow (QPACK) — h2o CWE-789 7.5 High 2026-07-10
CVE-2025-61684 Quicly has assertion failures — quicly CWE-20 7.5 High 2026-01-19
CVE-2024-45402 Picotls double free — picotls CWE-415 8.6 High 2024-10-11
CVE-2024-45396 Quicly assertion failures — quicly CWE-617 7.5 High 2024-10-11
CVE-2024-45403 H2O assertion failure when HTTP/3 requests are cancelled — h2o CWE-617 3.7 Low 2024-10-11
CVE-2024-45397 H2O alllows bypassing address-based access control with 0-RTT — h2o CWE-284 5.9 Medium 2024-10-11
CVE-2024-25622 H2O ignores headers configuration directives — h2o CWE-670 3.1 Low 2024-10-11
CVE-2023-50247 h2o QUIC state exhaustion DoS — h2o CWE-770 3.7 Low 2023-12-12
CVE-2023-41337 h2o vulnerable to TLS session resumption misdirection — h2o CWE-347 6.1 Medium 2023-12-12
CVE-2023-30847 H2O vulnerable to read from uninitialized pointer in the reverse proxy handler — h2o CWE-824 8.2 High 2023-04-27
CVE-2021-43848 Unititialized memory access in h2o — h2o CWE-908 7.4 High 2022-02-01

This page lists every published CVE security advisory associated with h2o. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.