h2oai h2o-3 Denial-of-Service Vulnerability in ImportFiles Endpoint

Vulnerability

A denial-of-service vulnerability has been identified in h2oai h2o-3 version 3.46.1. The issue arises in the '/3/ImportFiles' endpoint, which accepts a GET parameter named 'path'. An attacker can exploit this vulnerability by setting the 'path' parameter to reference itself recursively. This causes the server to repeatedly invoke the endpoint, eventually saturating the request queue and preventing the server from processing other incoming requests.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the server to become unresponsive to other requests.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.