CVE-2026-8751 | h2oai h2o-3 up to 7402 JAR Model.java importBinaryModel deserialization

SecurityVulns

A vulnerability classified as critical has been found in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization.

This vulnerability is reported as CVE-2026-8751. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More