#VU114025 Resource exhaustion in h2o - CVE-2025-8671

 

#VU114025 Resource exhaustion in h2o - CVE-2025-8671

Published: August 13, 2025 / Updated: September 12, 2025


Vulnerability identifier: #VU114025
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2025-8671
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
h2o
Software vendor:
h2o

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can send specially crafted HTTP requests to the affected server and consume its all available memory, leading to denial of service.



Remediation

Install updates from vendor's website.

External links