Back

CRITICAL

Remote Arbitrary File Write with Arbitrary Data in h2oai/h2o-3

Published Feb 2, 2026

Description

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the `/3/Frames/framename/export` endpoint. The impact of this vulnerability includes the potential for remote code execution and complete access to the system running h2o-3, as attackers can overwrite critical files such as private SSH keys or script files.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Feb 2, 2026
Updated Feb 2, 2026
Reserved Jun 13, 2024
CISA Vulnrichment
Updated Feb 2, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-WJ3H-WX8G-X699