Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-10550

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-10550
  • H2o » H2o » Version: 3.46.0.1
    cpe:2.3:a:h2o:h2o:3.46.0.1


Contact Us

Shodan ® - All rights reserved