CVE Tools

H2

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for H2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

H2 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
H2 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-081
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical220%
  • High440%
  • Medium440%

Latest CVEs

The 12 most recently published vulnerabilities affecting H2.

  1. CVE-2026-71554h2: Duplicate Host header could facilitate request smuggling5.3
  2. CVE-2025-57804h2 allows HTTP Request Smuggling due to illegal characters in headers5.3
  3. BDU:2024-02703Уязвимость библиотеки h2 языка программирования Rust в среде Tokio, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании5.3
  4. GHSA-q6cp-qfwq-4gcvh2 servers vulnerable to degradation of service with CONTINUATION Flood—
  5. GHSA-8r5v-vm4m-4g25Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)—
  6. CVE-2023-26964An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a...7.5
  7. CVE-2022-45868The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the w...8.4
  8. CVE-2022-23221H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a ...9.8
  9. CVE-2021-42392The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading...9.8
  10. CVE-2021-23463XML External Entity (XXE) Injection8.1
  11. CVE-2018-14335An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake databa...6.5
  12. CVE-2018-10054H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not desig...8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store