-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the httpUrlExists function which checks URL existence via unauthenticated HEAD requests without timeouts. This matches the CWE-1088 description of synchronous remote resource access without timeout. The function is directly called by calcTypeaheadMatches when handling HTTP/HTTPS typeahead requests, making it the entry point for the DoS attack vector described in CVE-2024-8062. The absence of timeout configuration in the HttpURLConnection setup leaves the connection vulnerable to hanging indefinitely when connecting to malicious servers.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| h2o | pip | ||
| ai.h2o:h2o-core | maven |
KEV Misses 88% of Exploited CVEs- Get the report