CVE-2015-5638: Dena h20
Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.
Affected products
- Dena h20: up to and including 1.4.4; up to and including 1.5.0
Published 2015-09-20. Last modified 2026-06-17.