CVE-2024-7768

Source
https://cve.org/CVERecord?id=CVE-2024-7768
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7768.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7768
Aliases
Published
2025-03-20T10:15:37.133Z
Modified
2026-03-12T17:23:48.487731Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability in the /3/ImportFiles endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, path, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7768.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.46.1"
            }
        ]
    }
]