Skip to content

H2O-3 security advisories

17 advisories · 2 critical or high in 12 months · latest Apr 23

17 advisories

DateAdvisory
Apr 23A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which only targets MySQL JDBC driver-specific da
CVE-2026-3960Critical9.8fixed in 3.46.0.10
Feb 2H2O has an External Control of File Name or Path vulnerability
CVE-2024-5986Critical9.1no fix yet
Sep 222025H2O affected by a deserialization vulnerability
CVE-2025-6544Critical9.8no fix yet
Mar 202025H2O Vulnerable to Arbitrary File Overwrite
CVE-2024-8616High8.2no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-8062High7.5no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-7765High7.5no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
CVE-2024-7768High7.5no fix yet
Mar 202025H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-6854High7.1no fix yet
Mar 202025H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-6863Medium6.5no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-10550High7.5no fix yet
Mar 202025H2O Deserialization of Untrusted Data Vulnerability
CVE-2024-10553Critical9.8fixed in 3.46.0.6
Mar 202025H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-10572High7.5no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-10549High7.5no fix yet
Sep 62024H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
CVE-2024-45758Critical9.1no fix yet
Jun 272024h2o vulnerable to unexpected POST request shutting down server
CVE-2024-5979High7.5no fix yet
Jun 62024Arbitrary system path lookup in h20
CVE-2024-5550Medium5.3no fix yet
Dec 142023External Control of File Name or Path in h2oai/h2o-3
CVE-2023-6569Critical9.3fixed in 3.46.0.1
About H2O-3

Distributed machine learning.

Packages watched: h2o (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.