CVE-2026-8751

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/submit/810107 Third Party Advisory VDB Entry
https://vuldb.com/vuln/364378 Third Party Advisory VDB Entry
https://vuldb.com/vuln/364378/cti Permissions Required VDB Entry
https://vulnplus-note.wetolink.com/share/b5nsQg6EcsBS Broken Link
Configurations

Configuration 1 (hide)

cpe:2.3:a:h2o:h2o:*:*:*:*:*:*:*:*

History

19 May 2026, 17:46

Type Values Removed Values Added
CPE cpe:2.3:a:h2o:h2o:*:*:*:*:*:*:*:*
First Time H2o
H2o h2o
References () https://vuldb.com/submit/810107 - () https://vuldb.com/submit/810107 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/364378 - () https://vuldb.com/vuln/364378 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/364378/cti - () https://vuldb.com/vuln/364378/cti - Permissions Required, VDB Entry
References () https://vulnplus-note.wetolink.com/share/b5nsQg6EcsBS - () https://vulnplus-note.wetolink.com/share/b5nsQg6EcsBS - Broken Link

17 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-17 12:16

Updated : 2026-05-19 17:46


NVD link : CVE-2026-8751

Mitre link : CVE-2026-8751

CVE.ORG link : CVE-2026-8751


JSON object : View

Products Affected

h2o

  • h2o
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data