H2
12 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for H2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
H2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High4
- Medium4
Latest CVEs
The 12 most recently published vulnerabilities affecting H2.
- CVE-2026-71554h2: Duplicate Host header could facilitate request smuggling5.3
- CVE-2025-57804h2 allows HTTP Request Smuggling due to illegal characters in headers5.3
- BDU:2024-02703Уязвимость библиотеки h2 языка программирования Rust в среде Tokio, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании5.3
- GHSA-q6cp-qfwq-4gcvh2 servers vulnerable to degradation of service with CONTINUATION Flood—
- GHSA-8r5v-vm4m-4g25Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)—
- CVE-2023-26964An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a...7.5
- CVE-2022-45868The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the w...8.4
- CVE-2022-23221H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a ...9.8
- CVE-2021-42392The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading...9.8
- CVE-2021-23463XML External Entity (XXE) Injection8.1
- CVE-2018-14335An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake databa...6.5
- CVE-2018-10054H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not desig...8.8
Product grouping is registry-driven, with AI assist and human review. How it works