CVE-2024-7768

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-7768 is a denial-of-service vulnerability affecting the `/3/ImportFiles` endpoint in h2oai/h2o-3 version 3.46.1. An attacker can exploit this issue by setting the endpoint's `path` parameter to recursively reference itself. The server, in response, will repeatedly call its own endpoint, leading to an excessive buildup in the request queue and rendering the server unable to process further requests.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share