ID:11917 - Exploit for Resource exhaustion in h2o - CVE-2025-8671
Published: August 30, 2025
h2o
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can send specially crafted HTTP requests to the affected server and consume its all available memory, leading to denial of service.