CVE-2024-5986Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the `/3/Frames/framename/export` endpoint. The impact of this vulnerability includes the potential for remote code execution and complete access to the system running h2o-3, as attackers can overwrite critical files such as private SSH keys or script files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-02); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-02: 3Mentions · 2026-02-03: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-03: 102-0202-03
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-023
Disclosure3
2026-02-031
Patch1
Full discourse4 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2024-5986: Remote Arbitrary File Write with ... H2O-3's `/3/Parse` + `/3/Frames/framename/export` chain enables trivial arbitrary file writes—weaponize to overwrite SSH... https://zerodaysignal.com/vulnerability/CVE-2024-5986 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2024-5986 exposes a remote arbitrary file write flaw in H2O‑3, enabling overwrite of files such as SSH configurations through a specific endpoint chain; no PoC, exploit, patch, or active exploitation is mentioned.

    0001071
    132 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    H2O Core has an External Control of File Name or Path vulnerability (CVE-2024-5986). This #SecurityVulnerability requires an update to version 3.46.0.1. Mitigate potential file system manipulation. #H2OCore #CVE https://www.pulsepatch.io/posts/cve-2024-5986-h2o-core-file-path-control

    Post summary

    H2O Core CVE-2024-5986 is an External Control of File Name or Path vulnerability; users should update to version 3.46.0.1 to mitigate potential file system manipulation.

    0000040
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2024-5986 H2O-3 Remote File Write Vulnerability via Endpoint Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-5986

    Post summary

    The text announces a new vulnerability (CVE‑2024‑5986) in H2O‑3 that allows remote file writes through endpoint manipulation, but provides no PoC, exploit, active exploitation, or patch details.

    0000084
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2024-5986: CRITICAL] Critical vulnerability found in h2o-3 version 3.46.0.1 enables remote attackers to write files on the server, leading to data theft and potential code execution attacks. #CyberSecurity#cve,CVE-2024-5986,#cybersecurity https://cvefind.com/CVE-2024-5986

    Post summary

    The post announces a critical remote file‑write vulnerability in h2o‑3 version 3.46.0.1 that could enable data theft or code execution, but provides no PoC, exploit, or patch details.

    0000088
    583 followersView on X

Explore more