PT-2026-41541 · H2O.Ai · H2O-3
Vulnplusbot
·
Published
2026-05-17
·
Updated
2026-05-18
·
CVE-2026-8751
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
h2oai h2o-3 versions prior to 7402
Description
A flaw in the JAR Handler component allows remote attackers to trigger deserialization by manipulating the
importBinaryModel() function within the h2o-core/src/main/java/hex/Model.java file. Deserialization is a process where data is converted from a binary format back into an object, which can be exploited to execute unauthorized code if the input is not properly validated.Recommendations
Update to a version later than 7402.
As a temporary workaround, restrict access to the
importBinaryModel() function to minimize the risk of exploitation.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H2O-3