H2o
Vendor:
First CVE: Jun 9, 2017 · Active for 9 years
28
Total CVEs
Bottom 1%
5.6
Avg CVEs / Year
Bottom 1%
8.0
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact H2o over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2017
9 years ago
Most Recent CVE
May 17, 2026
72 days ago
CVE Severity & Scoring
H2o28 CVEs
14%
50%
36%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network26 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (89.3%)
Unknown0 (0.0%)
Required3 (10.7%)
Privileges Required
Low2 (7.1%)
High0 (0.0%)
None26 (92.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6016CRITICAL An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature. | Nov 16, 2023 | 9.8 | 47 | NO | NO |
CVE-2026-8751CRITICAL A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Ha | May 17, 2026 | 9.8 | 36 | NO | NO |
CVE-2023-6038HIGH A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the | Nov 16, 2023 | 7.5 | 36 | NO | YES |
CVE-2025-6544CRITICAL A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises f | Sep 21, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-10769CRITICAL A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of t | Sep 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-10768CRITICAL A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulatio | Sep 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-8862CRITICAL A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the | Sep 14, 2024 | 9.8 | 30 | NO | NO |
CVE-2016-7835CRITICAL Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information. | Jun 9, 2017 | 9.1 | 30 | NO | NO |
CVE-2026-3960CRITICAL A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due | Apr 23, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-8750HIGH A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the | May 17, 2026 | 7.5 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For H2o
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.46.1 | 1 | 7.5 | 0.7% | 0 | 0 |
| 3.46.0.4 | 2 | 9.8 | 1.4% | 0 | 0 |
| 3.46.0.2 | 1 | 7.5 | 0.7% | 0 | 0 |
| 3.46.0.1 | 3 | 7.5 | 0.6% | 0 | 0 |
| 3.46.0 | 5 | 7.4 | 0.6% | 0 | 0 |
| 3.45.0.6386 | 1 | 7.1 | 0.2% | 0 | 0 |
| 3.40.0.4 | 2 | 6.8 | 0.8% | 0 | 0 |
| 2.1.0 | 1 | 9.1 | 2.2% | 0 | 0 |