CVE-2024-45397Patch(dena / h2o)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dena h2o systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect and prohibit HTTP requests conveyed by packets with a spoofed source address. This behavior allows attackers on the network to execute HTTP requests from addresses that are otherwise rejected by the address-based access control. The vulnerability has been addressed in commit 15ed15a. Users may disable the use of TCP FastOpen and QUIC to mitigate the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • h2o

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
h2o

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-21: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-21: 107-0207-21
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Classification over time
DateTotalLabels
2026-07-021
Patch1
2026-07-211
Disclosure1
Full discourse2 posts
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Disclosure

    Recent CVEs (July 21, 2026) impact network security. D-Link DNS-320 has an unrestricted upload vulnerability. H2O/QUIC DoS (CVE-2023-50247, CVE-2024-45396) and TLS/QUIC IP spoofing (CVE-2024-45397) risk data integrity & privacy in transit. #Cybersecurity #Vulnerabilities #News

    Post summary

    The text announces newly disclosed CVEs (CVE‑2023‑50247, CVE‑2024‑45396, CVE‑2024‑45397) that impact D-Link DNS‑320 with an unrestricted upload flaw, H2O/QUIC denial‑of‑service, and TLS/QUIC IP spoofing, posing data integrity and privacy risks.

    0000068
    15 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Recent QUIC/TLS/HTTP/3 vulnerabilities (e.g., CVE-2024-45397, CVE-2024-45402) expose data privacy & integrity to DoS attacks and access bypasses. Urgent patching is critical. #Cybersecurity #NetSec #Vulnerabilities

    Post summary

    The tweet alerts that newly discovered QUIC/TLS/HTTP‑3 CVEs can compromise data privacy and integrity, enabling DoS and access bypass, and urges urgent patching.

    0000062
    14 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdenah2o---

Explore more