PYSEC-2026-1440

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/h2o/PYSEC-2026-1440.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1440
Aliases
Published
2026-07-07T14:34:51Z
Modified
2026-07-07T17:46:12Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
Details

A vulnerability in the /3/ParseSetup endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.

References

Affected packages

PyPI / h2o

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.30.0.7
Last Affected
3.46.0.1

Affected versions

3.*
3.30.0.7
3.30.1.1
3.30.1.2
3.30.1.3
3.32.0.2
3.32.0.3
3.32.0.4
3.32.0.5
3.32.1.1
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.3
3.34.0.7
3.34.0.8
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3
3.46.0.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/h2o/PYSEC-2026-1440.yaml"