← Back to browse · API

CVE-2025-6507

Severity
CRITICAL
CVSS
9.8
EPSS
0.13617
Risk score
43.97
CISA KEV
No
PoC
No
Published
2025-09-01
Modified
2025-09-02
First seen
2026-08-07
Aliases
EUVD-2025-28743
Products
h2oai:h2oai/h2o-3 unspecified <3.46.0.8
Sources
euvd EUVD-2025-28743

Description

A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution and reading of system files. This issue affects the latest master branch version 3.47.0.99999. The vulnerability arises from the ability to bypass regular expression filters intended to prevent malicious parameter injection in JDBC connections. Attackers can manipulate spaces between parameters to evade detection, allowing for unauthorized file access and code execution. The vulnerability is addressed in version 3.46.0.8.

References