High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-8062
CVE-2024-8062
Description
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a HEAD request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
h2oPyPI | >= 3.2.0.1, <= 3.46.0 | — |
ai.h2o:h2o-coreMaven | >= 3.2.0.1, <= 3.46.0 | — |
Affected products
3- ghsa-coords2 versions
>= 3.2.0.1, <= 3.46.0+ 1 more
- (no CPE)range: >= 3.2.0.1, <= 3.46.0
- (no CPE)range: >= 3.2.0.1, <= 3.46.0
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/a04190d9-4acb-449a-9a7f-f1bf6be1ed23nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5c8j-g96x-cj78ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8062ghsaADVISORY
- github.com/h2oai/h2o-3/blob/047a4d617240a56e74f834207c65973d133391cb/h2o-core/src/main/java/water/persist/PersistManager.javaghsaWEB
News mentions
0No linked articles in our index yet.