GHSA-7qq7-pvm9-x8rf

Suggest an improvement
Source
https://github.com/advisories/GHSA-7qq7-pvm9-x8rf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7qq7-pvm9-x8rf
Aliases
Published
2025-03-20T12:32:39Z
Modified
2025-03-20T19:58:32.243509Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
Details

A vulnerability in the /3/ParseSetup endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-20T19:31:56Z",
    "severity": "HIGH",
    "nvd_published_at": "2025-03-20T10:15:17Z",
    "cwe_ids": [
        "CWE-1333"
    ]
}
References

Affected packages

PyPI / h2o

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.30.0.7
Last affected
3.46.0.1

Affected versions

3.*
3.30.0.7
3.30.1.1
3.30.1.2
3.30.1.3
3.32.0.2
3.32.0.3
3.32.0.4
3.32.0.5
3.32.1.1
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.3
3.34.0.7
3.34.0.8
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3
3.46.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json"

Maven / ai.h2o:h2o-core

Package

Name
ai.h2o:h2o-core
View open source insights on deps.dev
Purl
pkg:maven/ai.h2o/h2o-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.30.0.7
Last affected
3.46.0.1

Affected versions

3.*
3.30.0.7
3.30.1.1
3.30.1.2
3.30.1.3
3.32.0.1
3.32.0.2
3.32.0.3
3.32.0.4
3.32.0.5
3.32.1.1
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.1
3.34.0.3
3.34.0.4
3.34.0.5
3.34.0.6
3.34.0.7
3.34.0.8
3.35.0.2
3.36.0.1
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3
3.46.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json"