H2O-3GHSA-5w3j-gwgh-4rfv
H2O affected by a deserialization vulnerability
Critical9.8CVE-2025-6544 · Published Sep 22, 2025 · updated Jun 29, 2026
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.7, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handling of JDBC connection parameters, which can be exploited by bypassing regular expression checks and using double URL encoding. This issue impacts all users of the affected versions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| h2o PyPI | <= 3.46.0.7 | No fix yet |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2025-6544, PYSEC-2026-349
More H2O-3 advisories
All H2O-3| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 2 | H2O has an External Control of File Name or Path vulnerability | Critical9.1 | No fix yet |
| Mar 202025 | H2O Vulnerable to Arbitrary File Overwrite | High8.2 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Arbitrary File Overwrite via File Export | High7.1 | No fix yet |