Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1441
  • PyPI/h2o
H2O Vulnerable to Arbitrary File Overwrite 07 Jul
  • No fix available
  • Severity - 8.2 (High)
PYSEC-2026-1438
  • PyPI/h2o
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1443
  • PyPI/h2o
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1439
  • PyPI/h2o
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1442
  • PyPI/h2o
H2O Vulnerable to Execution of Arbitrary Files 07 Jul
  • No fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1436
  • PyPI/h2o
H2O Vulnerable to Arbitrary File Overwrite via File Export 07 Jul
  • No fix available
  • Severity - 7.1 (High)
PYSEC-2026-1444
  • PyPI/h2o
H2O Vulnerable to Denial of Service (DoS) and File Write 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1440
  • PyPI/h2o
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1445
  • PyPI/h2o
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1437
  • PyPI/h2o
h2o vulnerable to unexpected POST request shutting down server 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-1446
  • PyPI/h2o
Arbitrary system path lookup in h20 07 Jul
  • No fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-353
  • PyPI/h2o
H2O has an External Control of File Name or Path vulnerability 29 Jun
  • No fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-350
  • PyPI/h2o
External Control of File Name or Path in h2oai/h2o-3 29 Jun
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-352
  • PyPI/h2o
H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL 29 Jun
  • No fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-349
  • PyPI/h2o
H2O affected by a deserialization vulnerability 29 Jun
  • No fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-351
  • PyPI/h2o
H2O Deserialization of Untrusted Data Vulnerability 29 Jun
  • Fix available
  • Severity - 9.8 (Critical)