{"id":"PYSEC-2026-1438","summary":"H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request","details":"A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.","aliases":["CVE-2024-8062","GHSA-5c8j-g96x-cj78"],"modified":"2026-07-07T17:47:39.962990287Z","published":"2026-07-07T14:34:56.262232Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8062"},{"type":"PACKAGE","url":"https://github.com/h2oai/h2o-3"},{"type":"WEB","url":"https://github.com/h2oai/h2o-3/blob/047a4d617240a56e74f834207c65973d133391cb/h2o-core/src/main/java/water/persist/PersistManager.java#L302"},{"type":"WEB","url":"https://huntr.com/bounties/a04190d9-4acb-449a-9a7f-f1bf6be1ed23"},{"type":"PACKAGE","url":"https://pypi.org/project/h2o"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5c8j-g96x-cj78"}],"affected":[{"package":{"name":"h2o","ecosystem":"PyPI","purl":"pkg:pypi/h2o"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0.1"},{"last_affected":"3.46.0"}]}],"versions":["3.10.0.10","3.10.0.3","3.10.0.6","3.10.0.7","3.10.0.8","3.10.3.3","3.10.3.4","3.10.4.1","3.10.4.2","3.10.4.3","3.10.4.4","3.10.4.6","3.10.4.8","3.16.0.1","3.16.0.2","3.16.0.3","3.16.0.4","3.18.0.1","3.18.0.10","3.18.0.11","3.18.0.2","3.18.0.3","3.18.0.4","3.18.0.5","3.18.0.6","3.18.0.7","3.18.0.8","3.18.0.9","3.20.0.4","3.20.0.5","3.20.0.6","3.20.0.7","3.20.0.8","3.22.0.1","3.22.0.2","3.22.0.3","3.22.0.4","3.22.0.5","3.22.1.1","3.22.1.2","3.22.1.3","3.22.1.4","3.22.1.5","3.22.1.6","3.24.0.1","3.24.0.2","3.24.0.3","3.24.0.4","3.24.0.5","3.26.0.1","3.26.0.10","3.26.0.11","3.26.0.2","3.26.0.3","3.26.0.4","3.26.0.5","3.26.0.6","3.26.0.8","3.26.0.9","3.28.0.1","3.28.0.2","3.28.0.3","3.28.1.2","3.28.1.3","3.30.0.1","3.30.0.2","3.30.0.3","3.30.0.4","3.30.0.5","3.30.0.6","3.30.0.7","3.30.1.1","3.30.1.2","3.30.1.3","3.32.0.2","3.32.0.3","3.32.0.4","3.32.0.5","3.32.1.1","3.32.1.2","3.32.1.3","3.32.1.4","3.32.1.5","3.32.1.6","3.32.1.7","3.34.0.3","3.34.0.7","3.34.0.8","3.36.0.2","3.36.0.3","3.36.0.4","3.36.1.1","3.36.1.2","3.36.1.3","3.36.1.4","3.36.1.5","3.38.0.1","3.38.0.2","3.38.0.3","3.38.0.4","3.40.0.1","3.40.0.2","3.40.0.3","3.40.0.4","3.42.0.1","3.42.0.2","3.42.0.3","3.42.0.4","3.44.0.1","3.44.0.2","3.44.0.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/h2o/PYSEC-2026-1438.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}