GHSA-6w62-3jvj-mfj6

Suggest an improvement
Source
https://github.com/advisories/GHSA-6w62-3jvj-mfj6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6w62-3jvj-mfj6
Aliases
Published
2025-03-20T12:32:46Z
Modified
2026-07-07T17:56:47Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
Details

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running jobs. This issue arises from the improper handling of highly compressed data, leading to significant data amplification.

Database specific
{
    "cwe_ids":  [
        "CWE-409"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-03-20T19:56:42Z",
    "nvd_published_at":  "2025-03-20T10:15:36Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / h2o

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.32.1.2
Last Affected
3.46.0.2

Affected versions

3.*
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.3
3.34.0.7
3.34.0.8
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3
3.46.0.1
3.46.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json"

Maven / ai.h2o:h2o-core

Package

Name
ai.h2o:h2o-core
View open source insights on deps.dev
Purl
pkg:maven/ai.h2o/h2o-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.32.1.2
Last Affected
3.46.0.2

Affected versions

3.*
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.1
3.34.0.3
3.34.0.4
3.34.0.5
3.34.0.6
3.34.0.7
3.34.0.8
3.35.0.2
3.36.0.1
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3
3.46.0.1
3.46.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json"