High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-10550
CVE-2024-10550
Description
A vulnerability in the /3/ParseSetup endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
h2oPyPI | >= 3.30.0.7, <= 3.46.0.1 | — |
ai.h2o:h2o-coreMaven | >= 3.30.0.7, <= 3.46.0.1 | — |
Affected products
3- ghsa-coords2 versions
>= 3.30.0.7, <= 3.46.0.1+ 1 more
- (no CPE)range: >= 3.30.0.7, <= 3.46.0.1
- (no CPE)range: >= 3.30.0.7, <= 3.46.0.1
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/ef3f4d89-3b8b-4618-b134-cb93c1664ec6nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7qq7-pvm9-x8rfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-10550ghsaADVISORY
- github.com/h2oai/h2o-3/blob/51c25940ded8b7d0acc8f3f72329fd9dedbb3a34/h2o-core/src/main/java/water/api/ParseSetupHandler.javaghsaWEB
News mentions
0No linked articles in our index yet.