Vulnerabilities in h2oai
30 resultsVexday analysis
H2oai apresenta 29 CVEs catalogadas, com 9 críticas (CVSS ≥9.0), porém nenhuma sob ataque ativo confirmado até o momento. A fraqueza dominante é desserialização insegura (CWE-502), padrão em frameworks de machine learning, com 4 novos registros nos últimos 90 dias indicando descobertas recentes nesta superfície de ataque.
CVE-2024-10549HIGHDenial of Service by ReDOS in h2oai/h2o-3EPSS 0.6%CVE-2024-8616HIGHArbitrary File Overwrite in h2oai/h2o-3EPSS 0.5%CVE-2026-8750MEDIUMh2oai h2o-3 ImportFile API PersistNFS.java importFiles information disclosureEPSS 0.5%CVE-2025-10769MEDIUMh2oai h2o-3 H2 JDBC Driver ImportSQLTable deserializationEPSS 0.5%CVE-2024-8062HIGHDenial of Service in h2oai/h2o-3EPSS 0.4%CVE-2026-8751MEDIUMh2oai h2o-3 JAR Model.java importBinaryModel deserializationEPSS 0.4%CVE-2025-10768MEDIUMh2oai h2o-3 IBMDB2 JDBC Driver ImportSQLTable deserializationEPSS 0.4%CVE-2024-6863MEDIUMEncryption of Arbitrary Files with Attacker-Controlled Key in h2oai/h2o-3EPSS 0.3%CVE-2026-8752MEDIUMh2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access controlEPSS 0.3%CVE-2024-1456HIGHS3 Bucket Takeover in h2oai/h2o-3EPSS 0.2%