cvedb.io
CVE-2024-7765
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2025-03-20T10:15:36.867 · Last modified 2026-06-17T08:20:52.713

Summary

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running jobs. This issue arises from the improper handling of highly compressed data, leading to significant data amplification.

Affected products

h2o — h2o

Does this affect you?

Add your gear to cvedb and we'll alert you only when h2o ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.