CVE-2023-30847

HIGH

H2O <2.3.0-beta2 - Memory Corruption

Title source: llm
STIX 2.1

Description

H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream URL by reading from uninitialized pointer. This behavior can lead to crashes or leak of information to back end HTTP servers. Pull request number 3229 fixes the issue. The pull request has been merged to the `master` branch in commit f010336. Users should upgrade to commit f010336 or later.

Scores

CVSS v3 8.2
EPSS 0.0064
EPSS Percentile 70.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-824
Status published
Products (2)
dena/h2o 2.3.0 beta1 (2 CPE variants)
dena/h2o < 2.2.6
Published Apr 27, 2023
Tracked Since Feb 18, 2026