Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

h2oai/h2o-3 — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in h2oai/h2o-3, with AI-generated Chinese analysis, references, and POCs.

This page documents known software vulnerabilities and weaknesses associated with the h2oai/h2o-3 product, specifically focusing on security flaws, configuration errors, and potential attack vectors. It serves as a central reference for understanding the security posture of this open-source machine learning platform, aggregating data from various security advisories, patch notes, and community reports to provide a comprehensive view of risk factors. The content on this page collects information regarding critical and non-critical vulnerabilities affecting h2o-3 versions, covering the time range from initial public disclosures up to the most recent updates and fixes issued by the vendor. By consolidating these disparate sources, the page aims to offer clarity on the evolving threat landscape surrounding this specific software ecosystem, ensuring that administrators and developers have access to timely and accurate security intelligence. Visitors to this page can track the vendor's historical advisories to understand how quickly security issues are addressed, gain a deeper understanding of the specific weakness classes that impact the product, such as injection flaws or improper access controls, and look up the detailed vulnerability history of h2o-3 to assess risk and plan necessary remediation efforts effectively. This structured approach helps stakeholders make informed decisions about system hardening and upgrade paths.

Vendor: h2oai

CVE IDTitleCVSSSeverityPublished
CVE-2026-3960 Remote Code Execution in h2oai/h2o-3 CWE-94 9.8AICriticalAI2026-04-23
CVE-2024-5986 Remote Arbitrary File Write with Arbitrary Data in h2oai/h2o-3 CWE-73 9.8AICriticalAI2026-02-02
CVE-2025-6544 Deserialization Vulnerability in h2oai/h2o-3 CWE-502 9.8AICriticalAI2025-09-21
CVE-2025-5662 Deserialization Vulnerability in h2oai/h2o-3 CWE-502 9.8 -2025-09-02
CVE-2025-6507 Deserialization of Untrusted Data in h2oai/h2o-3 CWE-502 9.8 -2025-09-01
CVE-2024-10549 Denial of Service by ReDOS in h2oai/h2o-3 CWE-1333 7.5 -2025-03-20
CVE-2024-8062 Denial of Service in h2oai/h2o-3 CWE-1088 7.5 -2025-03-20
CVE-2024-7768 Denial of Service in h2oai/h2o-3 CWE-770 7.5 -2025-03-20
CVE-2024-6863 Encryption of Arbitrary Files with Attacker-Controlled Key in h2oai/h2o-3 CWE-749 9.1 -2025-03-20
CVE-2024-8616 Arbitrary File Overwrite in h2oai/h2o-3 CWE-73 8.6 -2025-03-20
CVE-2024-10550 Denial of Service by ReDOS in h2oai/h2o-3 CWE-1333 7.5 -2025-03-20
CVE-2024-6854 Arbitrary File Overwrite in h2oai/h2o-3 CWE-36 7.5 -2025-03-20
CVE-2024-10572 Denial of Service and Arbitrary File Write in h2oai/h2o-3 CWE-94 9.1 -2025-03-20
CVE-2024-10553 Jdbc Deserialization in h2oai/h2o-3 CWE-502 9.8 -2025-03-20
CVE-2024-7765 Denial of Service in h2oai/h2o-3 CWE-409 7.5 -2025-03-20
CVE-2024-5979 Denial of Service via Invalid Argument in h2oai/h2o-3 CWE-94 7.5AIHighAI2024-06-27
CVE-2024-5550 Exposure of Sensitive Information via Arbitrary System Path Lookup in h2oai/h2o-3 CWE-22 4.3AIMediumAI2024-06-06
CVE-2024-1456 S3 Bucket Takeover in h2oai/h2o-3 CWE-840 9.8 -2024-04-16
CVE-2023-6569 External Control of File Name or Path in h2oai/h2o-3 CWE-73 7.1AIHighAI2023-12-14
CVE-2023-6013 H2O Local File Include CWE-79 5.4 -2023-11-16
CVE-2023-6017 H2O S3 Bucket Takeover CWE-840 9.3 -2023-11-16
CVE-2023-6038 Local File Inclusion in h2oai/h2o-3 CWE-862 7.5 -2023-11-16
CVE-2023-6016 H2O Remote Code Execution via POJO Model Import CWE-94 8.8 -2023-11-16

All 23 known CVE vulnerabilities affecting h2oai/h2o-3 with full Chinese analysis, references, and POCs where available.