PT-2026-41541 · H2O.Ai · H2O-3

·

CVE-2026-8751

·

Published

2026-05-17

·

Updated

2026-05-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions h2oai h2o-3 versions prior to 7402
Description A flaw in the JAR Handler component allows remote attackers to trigger deserialization by manipulating the importBinaryModel() function within the h2o-core/src/main/java/hex/Model.java file. Deserialization is a process where data is converted from a binary format back into an object, which can be exploited to execute unauthorized code if the input is not properly validated.
Recommendations Update to a version later than 7402. As a temporary workaround, restrict access to the importBinaryModel() function to minimize the risk of exploitation.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8751

Affected Products

H2O-3