#VU114025 Resource exhaustion in h2o - CVE-2025-8671
Published: August 13, 2025 / Updated: September 12, 2025
h2o
h2o
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can send specially crafted HTTP requests to the affected server and consume its all available memory, leading to denial of service.