Vulnerabilidades en h2o
18 resultadosAnálisis Vexday
H2O apresenta 18 vulnerabilidades no total, com 8 publicadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma vulnerabilidade está sob exploração ativa nem classificada como crítica, reduzindo a urgência imediata, mas a fraqueza dominante (CWE-770 - alocação excessiva de recurso) sugere problemas estruturais de consumo de recursos que merecem atenção em ciclos de atualização.
CVE-2021-43848HIGHUnititialized memory access in h2oEPSS 2.7%CVE-2023-30847HIGHH2O vulnerable to read from uninitialized pointer in the reverse proxy handlerEPSS 0.9%CVE-2023-50247LOWh2o QUIC state exhaustion DoSEPSS 0.9%CVE-2024-45403LOWH2O assertion failure when HTTP/3 requests are cancelledEPSS 0.7%CVE-2024-45396HIGHQuicly assertion failuresEPSS 0.6%CVE-2024-45402HIGHPicotls double freeEPSS 0.5%CVE-2024-45397MEDIUMH2O alllows bypassing address-based access control with 0-RTTEPSS 0.4%CVE-2024-25622LOWH2O ignores headers configuration directivesEPSS 0.4%CVE-2026-55213HIGHh2o: musl libc stack overflow (QPACK)EPSS 0.3%CVE-2025-61684HIGHQuicly has assertion failuresEPSS 0.3%CVE-2026-54340HIGHh2o has HTTP/2 state amplificationEPSS 0.3%CVE-2026-44453HIGHh2o is vulnerable to musl libc stack overflowEPSS 0.3%CVE-2026-44433MEDIUMQuicly is vulnerable to memory exhaustionEPSS 0.3%CVE-2026-44435HIGHQuicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KBEPSS 0.3%CVE-2026-44436HIGHQuicly is vulnerable to connection state corruptionEPSS 0.3%CVE-2026-44452MEDIUMh2o is vulnerable to heap overrunEPSS 0.3%CVE-2023-41337MEDIUMh2o vulnerable to TLS session resumption misdirectionEPSS 0.2%CVE-2026-44434MEDIUMQuicly is vulnerable to stateless reset injectionEPSS 0.1%