{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-23T21:17:03.870","vulnerabilities":[{"cve":{"id":"CVE-2024-10550","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:17.390","lastModified":"2026-06-17T06:55:54.623","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive."},{"lang":"es","value":"Una vulnerabilidad en el endpoint `/3/ParseSetup` de h2oai/h2o-3 versión 3.46.0.1 permite un ataque de denegación de servicio (DoS). El endpoint aplica una expresión regular especificada por el usuario a una cadena controlable por este. Un atacante puede explotar esto para generar una complejidad ineficiente en las expresiones regulares, agotando los recursos del servidor y dejándolo inoperante."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"h2oai","product":"h2oai/h2o-3","versions":[{"version":"unspecified","lessThanOrEqual":"latest","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-20T17:52:08.944510Z","id":"CVE-2024-10550","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:h2o:h2o:3.46.0.1:*:*:*:*:*:*:*","matchCriteriaId":"64AF5618-ECAA-4801-BC14-0CF214B10BE1"}]}]}],"references":[{"url":"https://huntr.com/bounties/ef3f4d89-3b8b-4618-b134-cb93c1664ec6","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]}]}}]}