H2o
Vendor:
First CVE: Jan 16, 2016 · Active for 10 years
17
Total CVEs
More Total CVEs than 93% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
5.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact H2o over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2016
10 years ago
Most Recent CVE
Oct 11, 2024
651 days ago
CVE Severity & Scoring
H2o17 CVEs
24%
59%
12%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.9%)
Attack Complexity
Low15 (88.2%)
High2 (11.8%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low3 (17.6%)
High0 (0.0%)
None14 (82.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2016-7835CRITICAL Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information. | Jun 9, 2017 | 9.1 | 30 | NO | NO |
CVE-2018-0608CRITICAL Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors. | Jun 26, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-10868HIGH H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header. | Dec 22, 2017 | 7.5 | 26 | NO | NO |
CVE-2023-30847HIGH H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream UR | Apr 27, 2023 | 8.2 | 25 | NO | NO |
CVE-2017-10869HIGH Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors. | Dec 22, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-4817HIGH lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free an | Jun 19, 2016 | 7.5 | 25 | NO | NO |
CVE-2016-4864HIGH H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, m | May 12, 2017 | 7.5 | 24 | NO | NO |
CVE-2024-45403HIGH h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due t | Oct 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45397HIGH h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the | Oct 11, 2024 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
1 CVE
5.9% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For H2o
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.0 | 3 | 7.5 | 0.7% | 0 | 0 |
| 2.1.0 | 1 | 7.5 | 1.8% | 0 | 0 |
| 1.7.0 | 1 | 3.7 | 1.5% | 0 | 0 |