H2O is a developer-focused platform that provides open-source and commercial machine-learning and data-analytics tools, with a relatively narrow product footprint centered on its core H2O and Quicly offerings. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the attack surface inherent to data-processing systems that accept and deserialize untrusted input at scale. The recurring weakness classes—deserialization of untrusted data, code injection, improper input validation, and file-path control issues—are characteristic of systems that must parse and execute user-supplied data and configurations, creating pathways for both direct code execution and supply-chain risk through analytics pipelines. Defenders should treat H2O disclosures as high-priority given the severity tendency and the vendor's presence in research, finance, and enterprise analytics environments; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by H2o over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6016CRITICAL An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature. | Nov 16, 2023 | 9.8 | 47 | NO | NO |
CVE-2026-8751CRITICAL A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Ha | May 17, 2026 | 9.8 | 36 | NO | NO |
CVE-2023-6038HIGH A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the | Nov 16, 2023 | 7.5 | 36 | NO | YES |
CVE-2026-44436HIGH Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack th | Jul 16, 2026 | 7.5 | 34 | NO | NO |
CVE-2025-6544CRITICAL A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises f | Sep 21, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-10769CRITICAL A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of t | Sep 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-10768CRITICAL A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulatio | Sep 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-8862CRITICAL A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the | Sep 14, 2024 | 9.8 | 30 | NO | NO |
CVE-2016-7835CRITICAL Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information. | Jun 9, 2017 | 9.1 | 30 | NO | NO |
CVE-2026-3960CRITICAL A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due | Apr 23, 2026 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by H2o.
Media articles that mention a CVE ID that affects a product developed by H2o — matched by CVE ID, not by vendor name.