PT-2025-12046 · H2O.Ai · H2O-3

CVE-2024-10553

·

Published

2025-03-20

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions h2oai/h2o-3 versions 3.46.0.4 through 3.46.0.5
Description A vulnerability in the h2oai/h2o-3 REST API allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The issue exists in the endpoints "POST /99/ImportSQLTable" and "POST /3/SaveToHiveTable", where user-controlled JDBC URLs are passed to DriverManager.getConnection, leading to deserialization if a MySQL or PostgreSQL driver is available in the classpath.
Recommendations For versions 3.46.0.4 through 3.46.0.5, update to version 3.47.0 or 3.46.0.6 to resolve the issue. As a temporary workaround, consider restricting access to the "POST /99/ImportSQLTable" and "POST /3/SaveToHiveTable" endpoints until a patch is available. Avoid using user-controlled JDBC URLs in the affected API endpoints until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10553
GHSA-H7XG-CMPP-48HF
PYSEC-2026-351

Affected Products

H2O-3