Skip to main content
QUIETLYTIC
Vulnerability

h2oai h2o-3 Insecure Deserialization (CVE-2026-8751)

CVE-2026-8751 is a CVSS 7.3 high-severity insecure-deserialization flaw in h2o-3's model-import handler, publicly disclosed after the vendor did not respond to the report.

CVE-2026-8751
Threat Level
HIGH
CVSS
7.3
Status
Monitored
Confidence
Medium
Affected Products
h2oai h2o-3 (up to build 7402)

CVE-2026-8751 is a high-severity (CVSS 3.1 base 7.3) insecure-deserialization vulnerability in h2oai’s h2o-3, an open-source machine learning platform, affecting builds up to 7402.

What the vulnerability does

Per NVD’s description, the flaw is in importBinaryModel, a function in h2o-core/src/main/java/hex/Model.java responsible for loading a serialized model file. Manipulating this import path results in unsafe deserialization — a well-established vulnerability class where an attacker-supplied serialized object, rather than a trusted one, is deserialized without adequate validation, typically enabling remote code execution depending on what classes are reachable on the application’s classpath. NVD’s description states the attack can be carried out remotely and that exploit code has been publicly released.

Disclosure history

NVD’s own description notes the vendor was contacted early about this disclosure but did not respond in any way, after which the finding was released to the public. This is a meaningful data point distinct from the technical severity: no vendor acknowledgment means there is no confirmed timeline for an official fix, and organizations can’t rely on an upcoming patch as a mitigation plan.

What we don’t yet have

This record traces to a VulDB submission via NVD; no CISA KEV listing or vendor advisory is present in our ingested data. Confidence is medium, and we don’t have a confirmed fixed version — given the unacknowledged disclosure, check h2oai’s own release notes directly for whether builds after 7402 address this.

Why this matters

h2o-3 is used to load and run models that may originate from outside a fully trusted pipeline (shared model files, third-party training runs, CI artifacts) — exactly the scenario an insecure model-import deserialization bug threatens. Any deployment that imports binary model files from a source it doesn’t fully control should treat this as an active, unpatched risk given the lack of vendor response, and restrict model imports to trusted sources until a fix is confirmed.

Frequently Asked Questions

What is CVE-2026-8751? A CVSS 7.3 high-severity insecure-deserialization vulnerability in h2oai h2o-3’s binary model import handler, affecting builds up to 7402.

Has h2oai issued a fix for CVE-2026-8751? No confirmed fix is documented in our data — NVD notes the vendor did not respond to the initial disclosure.

Is CVE-2026-8751 being actively exploited? Public exploit code has been released per NVD’s description, but it is not listed in CISA’s Known Exploited Vulnerabilities catalog as of this writing.


Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulDB

Related intelligence


Analyst tools