Debian H2O vulnerabilities
10 known vulnerabilities affecting debian/h2o.
Total CVEs
10
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH5MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in dnsdist 1.8.2-2 (forky)2023
CVE-2023-44487 [HIGH] CVE-2023-44487: dnsdist - The HTTP/2 protocol allows a denial of service (server resource consumption) bec...
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2019-9515P3HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9515 [HIGH] CVE-2019-9515: h2o - Some HTTP/2 implementations are vulnerable to a settings flood, potentially lead...
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued,
debian
CVE-2019-9512P3HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9512 [HIGH] CVE-2019-9512: h2o - Some HTTP/2 implementations are vulnerable to ping floods, potentially leading t...
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Scope: local
bookworm: resolved (fixed in 2.2.5+dfsg2-3)
bullse
debian
CVE-2019-9514P3HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9514 [HIGH] CVE-2019-9514: h2o - Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading...
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
Scope: local
book
debian
CVE-2018-0608P3CRITICALCVSS 9.8fixed in h2o 2.2.5+dfsg1-1 (bookworm)2018
CVE-2018-0608 [CRITICAL] CVE-2018-0608: h2o - Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to exec...
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.2.5+dfsg1-1)
bullseye: resolved (fixed in 2.2.5+dfsg1-1)
debian
CVE-2025-8671P3HIGHCVSS 7.5fixed in varnish 7.7.2-1 (forky)2025
CVE-2025-8671 [HIGH] CVE-2025-8671: h2o - A mismatch caused by client-triggered server-sent stream resets between HTTP/2 s...
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker
debian
CVE-2017-10869P3MEDIUMCVSS 7.5fixed in h2o 2.2.3+dfsg-1 (bookworm)2017
CVE-2017-10869 [HIGH] CVE-2017-10869: h2o - Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to caus...
Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.2.3+dfsg-1)
bullseye: resolved (fixed in 2.2.3+dfsg-1)
debian
CVE-2017-10908P3MEDIUMCVSS 7.5fixed in h2o 2.2.4+dfsg-1 (bookworm)2017
CVE-2017-10908 [HIGH] CVE-2017-10908: h2o - H2O version 2.2.3 and earlier allows remote attackers to cause a denial of servi...
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
Scope: local
bookworm: resolved (fixed in 2.2.4+dfsg-1)
bullseye: resolved (fixed in 2.2.4+dfsg-1)
debian
CVE-2017-10868P3MEDIUMCVSS 7.5fixed in h2o 2.2.3+dfsg-1 (bookworm)2017
CVE-2017-10868 [HIGH] CVE-2017-10868: h2o - H2O version 2.2.2 and earlier allows remote attackers to cause a denial of servi...
H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.
Scope: local
bookworm: resolved (fixed in 2.2.3+dfsg-1)
bullseye: resolved (fixed in 2.2.3+dfsg-1)
debian
CVE-2017-10872P4MEDIUMCVSS 6.5fixed in h2o 2.2.4+dfsg-1 (bookworm)2017
CVE-2017-10872 [MEDIUM] CVE-2017-10872: h2o - H2O version 2.2.3 and earlier allows remote attackers to cause a denial of servi...
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.2.4+dfsg-1)
bullseye: resolved (fixed in 2.2.4+dfsg-1)
debian