CVE-2015-5638: Dena h20

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.

Affected products

  • Dena h20: up to and including 1.4.4; up to and including 1.5.0

Published 2015-09-20. Last modified 2026-06-17.