Dena's vulnerability footprint, while concentrated in a modest product portfolio, carries outsized prominence through its H2O HTTP server and PicoTLS cryptographic library, components that see broad adoption in performance-critical and embedded infrastructure contexts. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though the exposure is not characterized by widespread public exploitation. The recurring weakness classes—improper input validation, buffer-boundary violations, reachable assertions, and uninitialized pointer access—reflect the low-level demands of network protocol parsers and cryptographic implementations, where memory-safety lapses can cascade into system compromise. Defenders should monitor this vendor's releases closely for its server and TLS components in particular, as updates often address issues in foundational network layers that affect downstream products. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dena over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2016-7835CRITICAL Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information. | Jun 9, 2017 | 9.1 | 30 | NO | NO |
CVE-2024-45402CRITICAL Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, b | Oct 11, 2024 | 9.8 | 29 | NO | NO |
CVE-2018-0608CRITICAL Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors. | Jun 26, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-10868HIGH H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header. | Dec 22, 2017 | 7.5 | 26 | NO | NO |
CVE-2023-30847HIGH H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream UR | Apr 27, 2023 | 8.2 | 25 | NO | NO |
CVE-2017-10869HIGH Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors. | Dec 22, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-4817HIGH lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free an | Jun 19, 2016 | 7.5 | 25 | NO | NO |
CVE-2016-4864HIGH H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, m | May 12, 2017 | 7.5 | 24 | NO | NO |
CVE-2024-45403HIGH h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due t | Oct 11, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dena.
Media articles that mention a CVE ID that affects a product developed by Dena — matched by CVE ID, not by vendor name.