A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which only targets MySQL JDBC driver-specific da
Critical9.8CVE-2026-3960 · Published Apr 23, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| h2o PyPI | < 3.46.0.10 | 3.46.0.10 |
Details and references
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which only targets MySQL JDBC driver-specific dangerous parameters. An attacker can bypass these controls by switching the JDBC URL protocol to jdbc:postgresql: and exploiting PostgreSQL JDBC driver-specific parameters such as socketFactory and socketFactoryArg. This allows unauthenticated attackers to execute arbitrary code on the H2O-3 server with the privileges of the H2O-3 process. The issue is resolved in version 3.46.0.10.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the CVSS score
- Also known as
- CVE-2026-3960, GHSA-qmcv-hh7c-3m56
More H2O-3 advisories
All H2O-3| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 2 | H2O has an External Control of File Name or Path vulnerability CVE-2024-5986Critical9.1no fix yet | Critical9.1 | No fix yet |
| Sep 222025 | H2O affected by a deserialization vulnerability CVE-2025-6544Critical9.8no fix yet | Critical9.8 | No fix yet |
| Mar 202025 | H2O Vulnerable to Arbitrary File Overwrite CVE-2024-8616High8.2no fix yet | High8.2 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request CVE-2024-8062High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing CVE-2024-7765High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint CVE-2024-7768High7.5no fix yet | High7.5 | No fix yet |