H2O Vulnerable to Denial of Service (DoS) and File Write
High severity
GitHub Reviewed
Published
Mar 20, 2025
to the GitHub Advisory Database
•
Updated Oct 15, 2025
Description
Published by the National Vulnerability Database
Mar 20, 2025
Published to the GitHub Advisory Database
Mar 20, 2025
Reviewed
Mar 20, 2025
Last updated
Oct 15, 2025
In h2oai/h2o-3 version 3.46.0.1, the
run_toolcommand exposes classes in thewater.toolspackage through theastparser. This includes theXGBoostLibExtractToolclass, which can be exploited to shut down the server and write large files to arbitrary directories, leading to a denial of service.References