CVE-2026-8752
- EPSS 0.31%
- Veröffentlicht 17.05.2026 11:45:11
- Zuletzt bearbeitet 19.05.2026 17:44:01
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing...
CVE-2026-8751
- EPSS 0.41%
- Veröffentlicht 17.05.2026 11:30:10
- Zuletzt bearbeitet 19.05.2026 17:46:04
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attac...
CVE-2026-8750
- EPSS 0.5%
- Veröffentlicht 17.05.2026 10:45:10
- Zuletzt bearbeitet 19.05.2026 18:22:34
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disc...
CVE-2026-3960
- EPSS 0.94%
- Veröffentlicht 23.04.2026 08:47:48
- Zuletzt bearbeitet 19.05.2026 21:52:42
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism...
CVE-2025-10769
- EPSS 0.49%
- Veröffentlicht 21.09.2025 09:33:19
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The attack may be...
CVE-2025-10768
- EPSS 0.4%
- Veröffentlicht 21.09.2025 09:33:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack ma...
CVE-2025-6544
- EPSS 0.84%
- Veröffentlicht 21.09.2025 09:00:09
- Zuletzt bearbeitet 08.10.2025 20:05:02
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handling of JDBC connection parameters, which can be expl...
CVE-2024-10549
- EPSS 0.59%
- Veröffentlicht 20.03.2025 10:11:32
- Zuletzt bearbeitet 15.10.2025 13:15:35
A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-specified string to construct a regular expression, which is then applied to another user-specified strin...
CVE-2024-8062
- EPSS 0.45%
- Veröffentlicht 20.03.2025 10:11:04
- Zuletzt bearbeitet 26.03.2025 16:10:51
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by ...
CVE-2024-7768
- EPSS 0.73%
- Veröffentlicht 20.03.2025 10:10:48
- Zuletzt bearbeitet 15.10.2025 13:15:52
A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server...